[
  {
    "threat_severity": "Low",
    "public_date": "2018-07-07T00:00:00Z",
    "bugzilla": {
      "description": "audiofile: NULL pointer dereference in ModuleState::setup() in modules/ModuleState.cpp allows for denial of service via crafted file",
      "id": "1600367",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1600367"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert."
    ],
    "statement": "Red Hat Product Security has rated this issue as having a security impact of Low, and a future update may address this flaw.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "release_date": "2020-09-29T00:00:00Z",
        "advisory": "RHSA-2020:3877",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "package": "audiofile-1:0.3.6-9.el7"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 5",
        "fix_state": "Not affected",
        "package_name": "audiofile",
        "cpe": "cpe:/o:redhat:enterprise_linux:5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "audiofile",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "audiofile",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2018-13440\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-13440"
    ],
    "name": "CVE-2018-13440",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2018-09-16T00:00:00Z",
    "bugzilla": {
      "description": "audiofile: Heap-based buffer overflow in Expand3To4Module::run() when running sfconvert",
      "id": "1631088",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1631088"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-122",
    "details": [
      "An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "release_date": "2020-09-29T00:00:00Z",
        "advisory": "RHSA-2020:3877",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "package": "audiofile-1:0.3.6-9.el7"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 5",
        "fix_state": "Will not fix",
        "package_name": "audiofile",
        "cpe": "cpe:/o:redhat:enterprise_linux:5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "audiofile",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2018-17095\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-17095"
    ],
    "name": "CVE-2018-17095",
    "csaw": false
  },
  {
    "public_date": "2019-06-30T00:00:00Z",
    "bugzilla": {
      "description": "audiofile: a NULL pointer dereference in ulaw2linear_buf in G711.cpp in libmodules.a leading to DoS",
      "id": "1726067",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1726067"
    },
    "cvss3": {
      "cvss3_base_score": "0.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-476",
    "details": [
      "In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file."
    ],
    "statement": "This flaw was found to be a duplicate of CVE-2017-6838. Please see https://access.redhat.com/security/cve/CVE-2017-6838 for information about affected products and security errata.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 5",
        "fix_state": "Not affected",
        "package_name": "audiofile",
        "cpe": "cpe:/o:redhat:enterprise_linux:5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "audiofile",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "audiofile",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2019-13147\nhttps://nvd.nist.gov/vuln/detail/CVE-2019-13147"
    ],
    "name": "CVE-2019-13147",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2022-02-24T00:00:00Z",
    "bugzilla": {
      "description": "audiofile: memory leak in printinfo.c",
      "id": "2058371",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2058371"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L",
      "status": "draft"
    },
    "cwe": "CWE-401",
    "details": [
      "In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "audiofile",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Will not fix",
        "package_name": "audiofile",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2022-24599\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-24599"
    ],
    "name": "CVE-2022-24599",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2022-06-03T00:00:00Z",
    "bugzilla": {
      "description": "gimp: unhandled exception via a crafted XCF file may lead to DoS",
      "id": "2103202",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2103202"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-252",
    "details": [
      "An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS).",
      "A vulnerability was found in GIMP when loading a specially crafted XCF file. Due to an incorrect function return value, GIMP may access memory outside its address space, resulting in a denial of service."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2022-11-15T00:00:00Z",
        "advisory": "RHSA-2022:7978",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:2.99.8-3.el9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "gimp:2.8/gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "gimp:flatpak/gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2022-32990\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-32990"
    ],
    "name": "CVE-2022-32990",
    "mitigation": {
      "value": "Do not load untrusted XCF files.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-11-24T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the documentation. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2023-32668\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-32668"
    ],
    "name": "CVE-2023-32668",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2023-09-13T00:00:00Z",
    "bugzilla": {
      "description": "nss: new tlsfuzzer code can still detect timing issues in RSA operations",
      "id": "2238677",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2238677"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-208",
    "details": [
      "The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding as well as the length of the encrypted message was leaking through timing side-channel. By sending large number of attacker-selected ciphertexts, the attacker would be able to decrypt a previously intercepted PKCS#1 v1.5 ciphertext (for example, to decrypt a TLS session that used RSA key exchange), or forge a signature using the victim's key. The issue was fixed by implementing the implicit rejection algorithm, in which the NSS returns a deterministic random message in case invalid padding is detected, as proposed in the Marvin Attack paper. This vulnerability affects NSS < 3.61.",
      "A vulnerability was found in NSS. The interface between the cryptographic library (the softokn) and the rest of NSS is using PKCS#11, and the error reporting (erroring out when the PKCS#1 v1.5 padding checks fail) that PKCS#11 requires is very noisy, making it easy to detect over the network."
    ],
    "acknowledgement": "This issue was discovered by Hubert Kario (Red Hat).",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "nss",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "nss",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "nss",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "nss",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2023-4421\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-4421"
    ],
    "name": "CVE-2023-4421",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2023-10-24T00:00:00Z",
    "bugzilla": {
      "description": "openssl: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow",
      "id": "2248616",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2248616"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-325",
    "details": [
      "Issue summary: Generating excessively long X9.42 DH keys or checking\nexcessively long X9.42 DH keys or parameters may be very slow.\nImpact summary: Applications that use the functions DH_generate_key() to\ngenerate an X9.42 DH key may experience long delays.  Likewise, applications\nthat use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check()\nto check an X9.42 DH key or X9.42 DH parameters may experience long delays.\nWhere the key or parameters that are being checked have been obtained from\nan untrusted source this may lead to a Denial of Service.\nWhile DH_check() performs all the necessary checks (as of CVE-2023-3817),\nDH_check_pub_key() doesn't make any of these checks, and is therefore\nvulnerable for excessively large P and Q parameters.\nLikewise, while DH_generate_key() performs a check for an excessively large\nP, it doesn't check for an excessively large Q.\nAn application that calls DH_generate_key() or DH_check_pub_key() and\nsupplies a key or parameters obtained from an untrusted source could be\nvulnerable to a Denial of Service attack.\nDH_generate_key() and DH_check_pub_key() are also called by a number of\nother OpenSSL functions.  An application calling any of those other\nfunctions may similarly be affected.  The other functions affected by this\nare DH_check_pub_key_ex(), EVP_PKEY_public_check(), and EVP_PKEY_generate().\nAlso vulnerable are the OpenSSL pkey command line application when using the\n\"-pubcheck\" option, as well as the OpenSSL genpkey command line application.\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.",
      "A flaw was found in OpenSSL, which caused the generation or checking of long X9.42 DH keys or parameters to be much slower than expected. This issue could lead to a denial of service."
    ],
    "statement": "This vulnerability in OpenSSL is categorized as a low severity issue primarily because it requires specific conditions to exploit and doesn't directly result in a full Denial of Service (DoS). While the excessive time spent in DH key generation or verification could potentially cause delays, the impact is mitigated by the fact that it requires untrusted sources supplying large Q parameter values. Additionally, the OpenSSL SSL/TLS implementation remains unaffected, limiting the scope of potential attacks. Moreover, there are inherent limits on key length, which further restrict the potential for exploitation.",
    "affected_release": [
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2024-03-18T00:00:00Z",
        "advisory": "RHSA-2024:1316",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-openssl-1:1.1.1k-17.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2024-03-18T00:00:00Z",
        "advisory": "RHSA-2024:1316",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-openssl-1:1.1.1k-17.el7jbcs"
      },
      {
        "product_name": "JWS 5.7.8",
        "release_date": "2024-03-18T00:00:00Z",
        "advisory": "RHSA-2024:1319",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5.7",
        "package": "openssl"
      },
      {
        "product_name": "JWS 6.0.1",
        "release_date": "2024-03-18T00:00:00Z",
        "advisory": "RHSA-2024:1325",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.0",
        "package": "openssl"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2023-12-19T00:00:00Z",
        "advisory": "RHSA-2023:7877",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "openssl-1:1.1.1k-12.el8_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support",
        "release_date": "2024-01-11T00:00:00Z",
        "advisory": "RHSA-2024:0208",
        "cpe": "cpe:/o:redhat:rhel_eus:8.6",
        "package": "openssl-1:1.1.1k-12.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Extended Update Support",
        "release_date": "2024-01-10T00:00:00Z",
        "advisory": "RHSA-2024:0154",
        "cpe": "cpe:/o:redhat:rhel_eus:8.8",
        "package": "openssl-1:1.1.1k-12.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2024-04-30T00:00:00Z",
        "advisory": "RHSA-2024:2447",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.0.7-27.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2024-04-30T00:00:00Z",
        "advisory": "RHSA-2024:2447",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.0.7-27.el9"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5.7 on RHEL 7",
        "release_date": "2024-03-18T00:00:00Z",
        "advisory": "RHSA-2024:1318",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5.7::el7",
        "package": "jws5-tomcat-native-0:1.2.31-17.redhat_17.el7jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5.7 on RHEL 8",
        "release_date": "2024-03-18T00:00:00Z",
        "advisory": "RHSA-2024:1318",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5.7::el8",
        "package": "jws5-tomcat-native-0:1.2.31-17.redhat_17.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5.7 on RHEL 9",
        "release_date": "2024-03-18T00:00:00Z",
        "advisory": "RHSA-2024:1318",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5.7::el9",
        "package": "jws5-tomcat-native-0:1.2.31-17.redhat_17.el9jws"
      },
      {
        "product_name": "Text-Only JBCS",
        "release_date": "2024-03-18T00:00:00Z",
        "advisory": "RHSA-2024:1317",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "jbcs-httpd24-openssl"
      }
    ],
    "package_state": [
      {
        "product_name": "Cryostat 2",
        "fix_state": "Not affected",
        "package_name": "openssl",
        "cpe": "cpe:/a:redhat:cryostat:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2023-5678\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-5678\nhttps://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=34efaef6c103d636ab507a0cc34dca4d3aecc055\nhttps://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=710fee740904b6290fef0dd5536fbcedbc38ff0c\nhttps://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017\nhttps://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6\nhttps://www.openssl.org/news/secadv/20231106.txt"
    ],
    "name": "CVE-2023-5678",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2023-10-25T00:00:00Z",
    "bugzilla": {
      "description": "pip: Mercurial configuration injectable in repo revision when installing via pip",
      "id": "2250765",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2250765"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-77",
    "details": [
      "When installing a package from a Mercurial VCS URL  (ie \"pip install \nhg+...\") with pip prior to v23.3, the specified Mercurial revision could\nbe used to inject arbitrary configuration options to the \"hg clone\" \ncall (ie \"--config\"). Controlling the Mercurial configuration can modify\nhow and which repository is installed. This vulnerability does not \naffect users who aren't installing from Mercurial.",
      "A flaw was found in the Python pip package. The pip could allow a local authenticated attacker to bypass security restrictions due to a flaw when installing a package from a Mercurial VCS URL. By sending a specially crafted request, an attacker can inject arbitrary configuration options to the \"hg clone\" call to modify how and which repository is installed."
    ],
    "statement": "Mercurial is not available in RHEL 8 and 9,  so the vulnerability cannot be exploited. Without mercurial installed (the hg command), pip cannot clone and install from hg+http[s] URLs.",
    "affected_release": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2.4 for RHEL 8",
        "release_date": "2024-06-10T00:00:00Z",
        "advisory": "RHSA-2024:3781",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.4::el8",
        "package": "automation-controller-0:4.5.7-1.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.4 for RHEL 9",
        "release_date": "2024-06-10T00:00:00Z",
        "advisory": "RHSA-2024:3781",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.4::el9",
        "package": "automation-controller-0:4.5.7-1.el9ap"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 1.2",
        "fix_state": "Not affected",
        "package_name": "ansible-tower",
        "cpe": "cpe:/a:redhat:ansible_automation_platform"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3x-pyrsistent",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "python3.14-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python3.14-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python-pyrsistent",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/udi-rhel8",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Not affected",
        "package_name": "stf/prometheus-webhook-snmp",
        "cpe": "cpe:/a:redhat:stf:1.5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2023-5752\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-5752\nhttps://github.com/pypa/pip/pull/12306\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/F4PL35U6X4VVHZ5ILJU3PWUWN7H7LZXL/"
    ],
    "name": "CVE-2023-5752",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2025-06-03T12:59:10Z",
    "bugzilla": {
      "description": "cpython: python: Bypass extraction filter to modify file metadata outside extraction directory",
      "id": "2370013",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370013"
    },
    "cvss3": {
      "cvss3_base_score": "7.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-22",
    "details": [
      "Allows modifying some file metadata (e.g. last modified) with filter=\"data\" or file permissions (chmod) with filter=\"tar\" of files outside the extraction directory.\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature.\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.",
      "A flaw was found in CPython's tarfile module. This vulnerability allows modification of file metadata, such as timestamps or permissions, outside the intended extraction directory via maliciously crafted tar archives using the filter=\"data\" or filter=\"tar\" extraction filters."
    ],
    "statement": "The severity of this vulnerability was lowered due to the fact that successful exploitation requires the attacker to convince a privileged user or process to extract a malicious tar file. Since tar file extraction typically occurs in trusted contexts or with elevated privileges, the impact is reduced by the requirement of such access.\nVersions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide \"symlinks\" to the main python3 component, which provides the actual interpreter of the Python programming language.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10140",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "python3.12-0:3.12.9-2.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10026",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.11-0:3.11.13-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10031",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.12-0:3.12.11-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10128",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-70.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10128",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-70.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Extended Update Support Long-Life Add-On",
        "release_date": "2025-07-08T00:00:00Z",
        "advisory": "RHSA-2025:10602",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.8",
        "package": "python3-0:3.6.8-51.el8_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2025-07-08T00:00:00Z",
        "advisory": "RHSA-2025:10602",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "python3-0:3.6.8-51.el8_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2025-07-08T00:00:00Z",
        "advisory": "RHSA-2025:10602",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "python3-0:3.6.8-51.el8_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10136",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.21-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10148",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.11-0:3.11.11-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-02T00:00:00Z",
        "advisory": "RHSA-2025:10189",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.12-0:3.12.9-1.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10136",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.21-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10028",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.12-0:3.12.1-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10399",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.9-0:3.9.18-3.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-06-30T00:00:00Z",
        "advisory": "RHSA-2025:9918",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.11-0:3.11.7-1.el9_4.8"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1752066672"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1752065732"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-controller-rhel8:7.13.5-4.1752065732"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1752065737"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1752065731"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-operator-bundle:7.13.5-25"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1752065736"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-rhel8-operator:7.13.5-2.1752065733"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1752065755"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-management-console-rhel8:1.36.0-9"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-operator-bundle:1.36.0-12"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-rhel8-operator:1.36.0-18"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7"
      },
      {
        "product_name": "cert-manager operator for Red Hat OpenShift 1.16",
        "release_date": "2025-10-16T00:00:00Z",
        "advisory": "RHSA-2025:18219",
        "cpe": "cpe:/a:redhat:cert_manager:1.16::el9",
        "package": "cert-manager/jetstack-cert-manager-rhel9:v1.16.5-1760515757"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2025-08-06T00:00:00Z",
        "advisory": "RHSA-2025:13267",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:2.0.1-1754478727"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-aws-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-gcp-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-intel-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/granite-3.1-8b-lab-v2.1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/granite-3.1-8b-starter-v2.1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/instructlab-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/instructlab-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-granite-3-1-8b-lab-v2-1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-granite-3-1-8b-starter-v2-1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2024-12718\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-12718\nhttps://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f\nhttps://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a\nhttps://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a\nhttps://github.com/python/cpython/issues/127987\nhttps://github.com/python/cpython/issues/135034\nhttps://github.com/python/cpython/pull/135037\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"
    ],
    "name": "CVE-2024-12718",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted TTF file."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2024-25262\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-25262"
    ],
    "name": "CVE-2024-25262",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2025-11-06T18:36:21Z",
    "bugzilla": {
      "description": "github.com/containerd/containerd: containerd local privilege escalation",
      "id": "2413190",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2413190"
    },
    "cvss3": {
      "cvss3_base_score": "7.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-279",
    "details": [
      "containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an overly broad default permission vulnerability. Directory paths `/var/lib/containerd`, `/run/containerd/io.containerd.grpc.v1.cri` and `/run/containerd/io.containerd.sandbox.controller.v1.shim` were all created with incorrect permissions. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. Workarounds include updating system administrator permissions so the host can manually chmod the directories to not have group or world accessible permissions, or to run containerd in rootless mode.",
      "A local privilege escalation vulnerability has been discovered in containerd. This vulnerability is the result of an overly broad default permission which allows local users on the host to potentially access the metadata store, the content store and the contents of Kubernetes local volumes. The contents of volumes might include setuid binaries, which could allow a local user on the host to elevate privileges on the host."
    ],
    "affected_release": [
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2025-12-17T00:00:00Z",
        "advisory": "RHSA-2025:23428",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1.5.2-1765591231"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2025-12-17T00:00:00Z",
        "advisory": "RHSA-2025:23428",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-manager-rhel9:1.5.2-1765594821"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2025-12-17T00:00:00Z",
        "advisory": "RHSA-2025:23428",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1.5.2-1765591064"
      },
      {
        "product_name": "Network Observability (NETOBSERV) 1.11.1",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2900",
        "cpe": "cpe:/a:redhat:network_observ_optr:1.11::el9",
        "package": "network-observability/network-observability-cli-rhel9:1771226060"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-mustgather-rhel9:1785177359"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2343",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-mustgather-rhel9:1768627772"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25127",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/submariner-rhel9-operator:1780204322"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.7",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23248",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
        "package": "advanced-cluster-security/rhacs-central-db-rhel8:4.7"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.7",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23248",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
        "package": "advanced-cluster-security/rhacs-collector-rhel8:4.7"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.7",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23248",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:4.7"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.7",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23248",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
        "package": "advanced-cluster-security/rhacs-operator-bundle:4.7"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.7",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23248",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
        "package": "advanced-cluster-security/rhacs-rhel8-operator:4.7"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.7",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23248",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
        "package": "advanced-cluster-security/rhacs-roxctl-rhel8:4.7"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.7",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23248",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
        "package": "advanced-cluster-security/rhacs-scanner-v4-db-rhel8:4.7"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.7",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23248",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
        "package": "advanced-cluster-security/rhacs-scanner-v4-rhel8:4.7"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23644",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1.4.3-1765591609"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23644",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1.4.3-1765627216"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23644",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-manager-rhel9:1.4.3-1765594275"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23644",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1.4.3-1765591447"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.16",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5807",
        "cpe": "cpe:/a:redhat:openshift_ai:2.16::el8",
        "package": "rhoai/odh-model-controller-rhel8:1774286327"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3713",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-must-gather-rhel9:1770788873"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/cephcsi-rhel9:1782932114"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/cephcsi-rhel9-operator:1782931768"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/devicefinder-rhel9:1782932104"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/mcg-core-rhel9:1783536000"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/mcg-rhel9-operator:1783535989"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-client-console-rhel9:1783536515"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-client-rhel9-operator:1782932521"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1783018461"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-rhel9-operator:1783018421"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-blackbox-exporter-rhel9:1782932812"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cli-rhel9:1783537001"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1782932919"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-console-rhel9:1783537586"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1782932969"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1782933015"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1782933042"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-drbd-rhel9:1783537392"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-external-snapshotter-rhel9-operator:1782933235"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-external-snapshotter-sidecar-rhel9:1782933251"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1783537955"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1782933417"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-must-gather-rhel9:1783537742"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-rhel9-operator:1782933602"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-rhel9-operator:1783019377"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-volsync-plugin-mover-rhel9:1782934054"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-volsync-plugin-rhel9-operator:1782934036"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1782934284"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces (RHOSDS) 3.26",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2456",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.26::el9",
        "package": "devspaces/devspaces-rhel9-operator:1769797105"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces (RHOSDS) 3.26",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2456",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.26::el9",
        "package": "devspaces/traefik-rhel9:1769638073"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3122",
        "cpe": "cpe:/a:redhat:openstack:16.2::el8",
        "package": "rhosp-rhel8/osp-director-agent:1770909763"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3122",
        "cpe": "cpe:/a:redhat:openstack:16.2::el8",
        "package": "rhosp-rhel8/osp-director-operator:1770909984"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "release_date": "2025-12-09T00:00:00Z",
        "advisory": "RHSA-2025:22955",
        "cpe": "cpe:/a:redhat:openstack:17.1::el9",
        "package": "rhosp-rhel9/osp-director-agent:1.3.1-1765298349"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "release_date": "2025-12-09T00:00:00Z",
        "advisory": "RHSA-2025:22955",
        "cpe": "cpe:/a:redhat:openstack:17.1::el9",
        "package": "rhosp-rhel9/osp-director-operator:1.3.1-1765298349"
      }
    ],
    "package_state": [
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Not affected",
        "package_name": "assisted/agent-preinstall-image-builder-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "rhai/assisted-installer-agent-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "rhai/assisted-installer-controller-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Compliance Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-compliance-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-monitor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Custom Metric Autoscaler operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
      },
      {
        "product_name": "Deployment Validation Operator",
        "fix_state": "Affected",
        "package_name": "dvo/deployment-validation-rhel8-operator",
        "cpe": "cpe:/a:redhat:deployment_validator_operator"
      },
      {
        "product_name": "File Integrity Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-compliance-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1"
      },
      {
        "product_name": "Gatekeeper 3",
        "fix_state": "Not affected",
        "package_name": "gatekeeper/gatekeeper-rhel9",
        "cpe": "cpe:/a:redhat:gatekeeper:3"
      },
      {
        "product_name": "Kernel Module Management Operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "kmm/kernel-module-management-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:kernel_module_management:2"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/loki-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/loki-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/lokistack-gateway-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/opa-openshift-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/loki-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/loki-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/lokistack-gateway-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/opa-openshift-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Not affected",
        "package_name": "lvms4/lvms-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/machine-deletion-remediation-operator-bundle",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/machine-deletion-remediation-rhel9-operator",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-hook-runner-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-log-reader-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-api-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-cli-download-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-openstack-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-operator-bundle",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-ova-provider-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-ova-proxy-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-populator-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-rhv-populator-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-validation-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-virt-v2v-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-vsphere-xcopy-volume-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-api-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-cli-download-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-openstack-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-operator-bundle",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-ova-provider-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-ova-proxy-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-populator-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-rhv-populator-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-validation-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-virt-v2v-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-vsphere-xcopy-volume-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-agent-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-agent-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-controller-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-controller-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-service-8-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-service-9-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Will not fix",
        "package_name": "multicluster-engine/must-gather-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/node-healthcheck-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "helm",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-jenkins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/openshift-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-entrypoint-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-entrypoint-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-events-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-events-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-nop-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-nop-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-resolvers-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-resolvers-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-results-api-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-results-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-results-retention-policy-agent-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-results-retention-policy-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-results-watcher-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-results-watcher-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-sidecarlogresults-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-sidecarlogresults-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-webhook-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-webhook-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-workingdirinit-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-workingdirinit-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Will not fix",
        "package_name": "openshift-serverless-1/kn-client-cli-artifacts-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Will not fix",
        "package_name": "openshift-serverless-1/kn-client-kn-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Will not fix",
        "package_name": "openshift-serverless-1/kn-plugin-func-func-util-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Will not fix",
        "package_name": "openshift-serverless-1/serverless-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Will not fix",
        "package_name": "openshift-serverless-1/serverless-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-cni-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-pilot-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-sail-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh-tech-preview/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Power monitoring for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-power-monitoring/power-monitoring-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_power_monitoring"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-grafana-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multicloud-integrations-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multiclusterhub-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multicluster-operators-channel-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multicluster-operators-subscription-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/observatorium-rhel9-operator",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/submariner-operator-bundle",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/aap-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Build of Kueue",
        "fix_state": "Not affected",
        "package_name": "kueue/kueue-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:kueue_operator:1"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Affected",
        "package_name": "rhceph/rhceph-promtail-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Affected",
        "package_name": "rhceph/rhceph-promtail-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Certification Program for Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "rhcertification/redhat-certification-baremetal",
        "cpe": "cpe:/a:redhat:certifications:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "container-tools:rhel8/buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "container-tools:rhel8/conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "container-tools:rhel8/podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "container-tools:rhel8/skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Will not fix",
        "package_name": "rhelai1/bootc-gcp-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Will not fix",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-launcher-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-launcher-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "cri-o",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "microshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/cnf-tests-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/cnf-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/container-networking-plugins-microshift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/kube-compare-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/lifecycle-agent-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/metallb-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/metallb-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/microshift-bootc-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/network-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/numaresources-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/numaresources-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/numaresources-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/oc-mirror-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/oc-mirror-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-csr-approver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-csr-approver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-node-agent-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-node-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-orchestrator-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-orchestrator-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ansible-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-aws-ebs-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-aws-ebs-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-disk-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-disk-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-file-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-file-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-baremetal-installer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli-artifacts",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-autoscaler-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-console",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-console-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-container-networking-plugins-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-driver-manila-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-driver-shared-resource-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-external-provisioner",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-external-provisioner-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-external-provisioner-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-deployer",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-deployer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-builder",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-builder-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-registry",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-helm-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-helm-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-hyperkube",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-hyperkube-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-installer-altinfra-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-installer-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-installer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-kube-proxy",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-kube-proxy-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-local-storage-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-api-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-api-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-config-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-node-feature-discovery",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-node-feature-discovery-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-catalogd-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-catalogd-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-operator-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-operator-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-rukpak-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-rukpak-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openstack-cinder-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openstack-cloud-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-framework-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-lifecycle-manager",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-lifecycle-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-registry",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-sdk-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-sdk-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ovn-kubernetes-microshift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ovn-kubernetes-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-powervs-block-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-powervs-block-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-secrets-store-csi-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tools-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vmware-vsphere-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-syncer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ptp-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ztp-site-generate-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift-clients",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "podman",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "redhat/redhat-operator-index",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/devspaces-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/udi-base-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/udi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Not affected",
        "package_name": "openshift4-wincw/windows-machine-config-operator-bundle",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Not affected",
        "package_name": "openshift4-wincw/windows-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/argocd-agent-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/argocd-extensions-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/argocd-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/argocd-rhel9",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/argo-rollouts-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/console-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/dex-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/gitops-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/gitops-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/gitops-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/multus-dynamic-networks-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/wasp-agent-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/osp-director-downloader",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/osp-director-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel9/osp-director-downloader",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel9/osp-director-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/cinder-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/ee-openstack-ansible-ee-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/glance-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/heat-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/horizon-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/infra-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/ironic-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/keystone-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/manila-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/mysqld-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/neutron-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/openstack-baremetal-agent-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/openstack-baremetal-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/openstack-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/openstack-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/openstack-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/ovn-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/prometheus-podman-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/rabbitmq-cluster-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/sg-core-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/watcher-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/policy-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2024-25621\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-25621\nhttps://github.com/containerd/containerd/blob/main/docs/rootless.md\nhttps://github.com/containerd/containerd/commit/7c59e8e9e970d38061a77b586b23655c352bfec5\nhttps://github.com/containerd/containerd/security/advisories/GHSA-pwhc-rpq9-4c8w"
    ],
    "name": "CVE-2024-25621",
    "mitigation": {
      "value": "The system administrator on the host can manually chmod the directories to not\nhave group or world accessible permissions:\n```\nchmod 700 /var/lib/containerd\nchmod 700 /run/containerd/io.containerd.grpc.v1.cri\nchmod 700 /run/containerd/io.containerd.sandbox.controller.v1.shim\n```\nAn alternative mitigation would be to run containerd in rootless mode.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-04-07T17:18:01Z",
    "bugzilla": {
      "description": "edk2: Out-of-bounds Read in EDK2",
      "id": "2358006",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2358006"
    },
    "cvss3": {
      "cvss3_base_score": "4.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.",
      "A flaw was found in EDK2. This vulnerability allows an attacker to cause an out-of-bounds read, potentially leading to a loss of integrity and/or availability via a crafted data pointer and length sent over an adjacent network."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2024-38797\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-38797\nhttps://github.com/tianocore/edk2/security/advisories/GHSA-4wjw-6xmf-44xf"
    ],
    "name": "CVE-2024-38797",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-09-19T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2024-38805\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-38805"
    ],
    "name": "CVE-2024-38805",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-17T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2024-38999\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-38999"
    ],
    "name": "CVE-2024-38999",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-03-17T21:32:37Z",
    "bugzilla": {
      "description": "containerd: containerd has an integer overflow in User ID handling",
      "id": "2353043",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2353043"
    },
    "cvss3": {
      "cvss3_base_score": "4.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This could cause unexpected behavior for environments that require containers to run as a non-root user. This bug has been fixed in containerd 1.6.38, 1.7.27, and 2.04. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.",
      "A flaw was found in containerd package. Containers launched with a User set as a UID:GID larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This issue could cause unexpected behavior for environments that require containers to run as a non-root user."
    ],
    "statement": "For Red Hat OpenShift GitOps and OpenShift Container Platform deployments, image sources are controlled through OpenShift's Image configuration and RBAC policies. Administrators can restrict image imports to trusted registries using allowedRegistriesForImport and registrySources configuration.In typical GitOps deployments, application images are pulled from pre-approved registries configured by platform administrators.",
    "affected_release": [
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/cephcsi-rhel9:1782932114"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/cephcsi-rhel9-operator:1782931768"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/devicefinder-rhel9:1782932104"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/mcg-core-rhel9:1783536000"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/mcg-rhel9-operator:1783535989"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-client-console-rhel9:1783536515"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-client-rhel9-operator:1782932521"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1783018461"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-rhel9-operator:1783018421"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-blackbox-exporter-rhel9:1782932812"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cli-rhel9:1783537001"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1782932919"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-console-rhel9:1783537586"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1782932969"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1782933015"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1782933042"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-drbd-rhel9:1783537392"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-external-snapshotter-rhel9-operator:1782933235"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-external-snapshotter-sidecar-rhel9:1782933251"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1783537955"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1782933417"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-must-gather-rhel9:1783537742"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-rhel9-operator:1782933602"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-rhel9-operator:1783019377"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-volsync-plugin-mover-rhel9:1782934054"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-volsync-plugin-rhel9-operator:1782934036"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1782934284"
      }
    ],
    "package_state": [
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "rhai-tech-preview/assisted-installer-agent-rhel8",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "cert-manager/jetstack-cert-manager-acmesolver-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "cert-manager/jetstack-cert-manager-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "Deployment Validation Operator",
        "fix_state": "Fix deferred",
        "package_name": "deployment-validation-operator-container",
        "cpe": "cpe:/a:redhat:deployment_validator_operator"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Fix deferred",
        "package_name": "migration-toolkit-virtualization/mtv-validation-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Fix deferred",
        "package_name": "multicluster-engine/assisted-service-8-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Fix deferred",
        "package_name": "multicluster-engine/assisted-service-9-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Fix deferred",
        "package_name": "network-observability/network-observability-cli-rhel9",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Fix deferred",
        "package_name": "jenkins-agent-base-container",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Fix deferred",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/client-kn-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1-func-utils-rhel8-container",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/kn-client-cli-artifacts-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/kn-client-kn-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/kn-plugin-func-func-util-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/serverless-ingress-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/serverless-kn-operator-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/serverless-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/serverless-openshift-kn-rhel8-operator",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-istio-operator-container",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "rhacm2/multicloud-integrations-rhel8",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "rhacm2/multicluster-operators-channel-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "rhacm2/multicluster-operators-subscription-rhel8",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "rhacm2/prometheus-rhel8",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Fix deferred",
        "package_name": "advanced-cluster-security/rhacs-central-db-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Fix deferred",
        "package_name": "advanced-cluster-security/rhacs-main-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Fix deferred",
        "package_name": "advanced-cluster-security/rhacs-rhel8-operator",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Fix deferred",
        "package_name": "advanced-cluster-security/rhacs-roxctl-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Fix deferred",
        "package_name": "advanced-cluster-security/rhacs-scanner-v4-db-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Fix deferred",
        "package_name": "advanced-cluster-security/rhacs-scanner-v4-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Fix deferred",
        "package_name": "rhdh-orchestrator-dev-preview-beta/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-launcher-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-operator-framework-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "stargz-snapshotter",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Fix deferred",
        "package_name": "openshift-gitops-1/argocd-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Fix deferred",
        "package_name": "openshift-gitops-1/argocd-rhel9",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat Openshift Sandboxed Containers",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9",
        "cpe": "cpe:/a:redhat:openshift_sandboxed_containers:1"
      },
      {
        "product_name": "Red Hat Openshift Sandboxed Containers",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-cloud-api-adaptor-webhook-rhel9",
        "cpe": "cpe:/a:redhat:openshift_sandboxed_containers:1"
      },
      {
        "product_name": "Red Hat Openshift Sandboxed Containers",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_sandboxed_containers:1"
      },
      {
        "product_name": "Red Hat Openshift Sandboxed Containers",
        "fix_state": "Fix deferred",
        "package_name": "osc-podvm-builder-container",
        "cpe": "cpe:/a:redhat:openshift_sandboxed_containers:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Fix deferred",
        "package_name": "container-native-virtualization/multus-dynamic-networks-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat Trusted Application Pipeline",
        "fix_state": "Fix deferred",
        "package_name": "rhtap-cli/rhtap-cli-rhel9",
        "cpe": "cpe:/a:redhat:trusted_application_pipeline:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2024-40635\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-40635\nhttps://github.com/containerd/containerd/commit/05044ec0a9a75232cad458027ca83437aae3f4da\nhttps://github.com/containerd/containerd/commit/1a43cb6a1035441f9aca8f5666a9b3ef9e70ab20\nhttps://github.com/containerd/containerd/commit/cf158e884cfe4812a6c371b59e4ea9bc4c46e51a\nhttps://github.com/containerd/containerd/security/advisories/GHSA-265r-hfxg-fhmg"
    ],
    "name": "CVE-2024-40635",
    "mitigation": {
      "value": "To mitigate this vulnerability, ensure that only trusted images are used and that only trusted users have permissions to import images.\nTo implement the recommended controls in OpenShift:\n1. Restrict allowed registries at the cluster level by configuring image.config.openshift.io/cluster with allowedRegistriesForImport and registrySources.allowedRegistries.\n2. To find out who can pull/import container images into OpenShift for that namespace Based on RBAC permissions: `oc adm policy who-can create imagestreamimports -n <namespace>`\n3. Enforce image signature verification using sigstore or cluster image signature policies.\n4. For GitOps deployments, use Gatekeeper/OPA policies to enforce that ArgoCD Applications reference only approved registries.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-20T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2024-42040\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-42040"
    ],
    "name": "CVE-2024-42040",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2024-10-24T00:00:00Z",
    "bugzilla": {
      "description": "assimp: heap-buffer-overflow in OpenDDLParser::parseStructure",
      "id": "2321628",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2321628"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-122",
    "details": [
      "A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.",
      "A flaw was found in the Assimp asset import library. An attacker my be able to trigger a buffer overflow condition via specially-crafted OpenGEX files. This may lead to a denial of service or other unexpected behavior."
    ],
    "statement": "The heap-buffer-overflow vulnerability in the Assimp library is classified as moderate because, while it can cause memory corruption or application crashes, it does not inherently lead to arbitrary code execution or privilege escalation. Exploitation requires a crafted OpenGEX file, limiting the attack surface to scenarios where untrusted files are processed by the affected function.\nIt's important to note that this vulnerability does not impact any Red Hat products, indicating that Red Hat's software stack is unaffected by this specific CVE.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "qt5-qt3d",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2024-48424\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-48424\nhttps://github.com/assimp/assimp/issues/5787"
    ],
    "name": "CVE-2024-48424",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2024-06-05T00:00:00Z",
    "bugzilla": {
      "description": "libaom: Integer overflow in internal function img_alloc_helper",
      "id": "2292396",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2292396"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-20",
    "details": [
      "Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers:\n*  Calling aom_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid.\n*  Calling aom_img_wrap() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid.\n*  Calling aom_img_alloc_with_border() with a large value of the d_w, d_h, align, size_align, or border parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid.",
      "An integer overflow flaw was found in the libaom internal img_alloc_helper function. This issue can lead to a heap buffer overflow."
    ],
    "statement": "Firefox and Thunderbird are likely not affected by this CVE. Similar to Chrome, they filter out values that are large enough to trigger the overflow before passing them to the underlying libraries.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "firefox:flatpak/firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "thunderbird:flatpak/thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "firefox:flatpak/firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2024-5171\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-5171\nhttps://issues.chromium.org/issues/332382766"
    ],
    "name": "CVE-2024-5171",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2024-10-16T17:09:23Z",
    "bugzilla": {
      "description": "openssl: Low-level invalid GF(2^m) parameters lead to OOB memory access",
      "id": "2319236",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2319236"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted\nexplicit values for the field polynomial can lead to out-of-bounds memory reads\nor writes.\nImpact summary: Out of bound memory writes can lead to an application crash or\neven a possibility of a remote code execution, however, in all the protocols\ninvolving Elliptic Curve Cryptography that we're aware of, either only \"named\ncurves\" are supported, or, if explicit curve parameters are supported, they\nspecify an X9.62 encoding of binary (GF(2^m)) curves that can't represent\nproblematic input values. Thus the likelihood of existence of a vulnerable\napplication is low.\nIn particular, the X9.62 encoding is used for ECC keys in X.509 certificates,\nso problematic inputs cannot occur in the context of processing X.509\ncertificates.  Any problematic use-cases would have to be using an \"exotic\"\ncurve encoding.\nThe affected APIs include: EC_GROUP_new_curve_GF2m(), EC_GROUP_new_from_params(),\nand various supporting BN_GF2m_*() functions.\nApplications working with \"exotic\" explicit binary (GF(2^m)) curve parameters,\nthat make it possible to represent invalid field polynomials with a zero\nconstant term, via the above or similar APIs, may terminate abruptly as a\nresult of reading or writing outside of array bounds.  Remote code execution\ncannot easily be ruled out.\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.",
      "A flaw was found in OpenSSL. Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds memory reads or writes. X9.62 encoding is used for ECC keys in X.509 certificates, so problematic inputs cannot occur in the context of processing X.509 certificates. Any problematic use-cases would have to be using an \"exotic\" curve encoding.\nApplications working with \"exotic\" explicit binary (GF(2^m)) curve parameters make it possible to represent invalid field polynomials with a zero constant term via the affected APIs (EC_GROUP_new_curve_GF2m(), EC_GROUP_new_from_params(),\nand various supporting BN_GF2m_*() functions) may terminate abruptly as a result of reading or writing outside of array bounds."
    ],
    "statement": "Openssl, compat-openssl10, and compat-openssl11 in Red Hat Enterprise Linux 7, 8, 9 are unaffected by this flaw, because the vulnerability is in code for binary field elliptic curves, which RHEL has never enabled.",
    "package_state": [
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp-backend-container",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2024-9143\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-9143\nhttps://github.com/openssl/openssl/commit/72ae83ad214d2eef262461365a1975707f862712\nhttps://github.com/openssl/openssl/commit/bc7e04d7c8d509fb78fc0e285aa948fb0da04700\nhttps://github.com/openssl/openssl/commit/c0d3e4d32d2805f49bec30547f225bc4d092e1f4\nhttps://github.com/openssl/openssl/commit/fdf6723362ca51bd883295efe206cb5b1cfa5154\nhttps://github.openssl.org/openssl/extended-releases/commit/8efc0cbaa8ebba8e116f7b81a876a4123594d86a\nhttps://github.openssl.org/openssl/extended-releases/commit/9d576994cec2b7aa37a91740ea7e680810957e41\nhttps://openssl-library.org/news/secadv/20241016.txt"
    ],
    "name": "CVE-2024-9143",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2024-10-22T16:34:39Z",
    "bugzilla": {
      "description": "python: Virtual environment (venv) activation scripts don't quote paths",
      "id": "2321440",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2321440"
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-428",
    "details": [
      "A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment \"activation\" scripts (ie \"source venv/bin/activate\"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie \"./venv/bin/python\") are not affected.",
      "A vulnerability has been found in the Python `venv` module and CLI. Path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment \"activation\" scripts, for example, \"source venv/bin/activate\". This flaw allows attacker-controlled virtual environments to run commands when the virtual environment is activated."
    ],
    "statement": "This vulnerability in the Python `venv` module is rated as moderate rather than important because it relies on a specific set of conditions to be exploitable, limiting its impact. An attacker would need to have control over the virtual environment creation process and access to the environment setup, which is less common in typical usage scenarios. Furthermore, the vulnerability only poses a risk if users activate the malicious virtual environment through `source venv/bin/activate` or similar scripts, as direct invocation of the virtual environment without activation (`./venv/bin/python`) is not affected.\nVersions of python36:3.6/python36 and python39:3.9/python39 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide \"symlinks\" to the main python3 component, which provides the actual interpreter of the Python programming language.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-05-13T00:00:00Z",
        "advisory": "RHBA-2025:6294",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "python3.12-0:3.12.9-1.el10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2024-12-04T00:00:00Z",
        "advisory": "RHSA-2024:10779",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-69.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2024-12-12T00:00:00Z",
        "advisory": "RHSA-2024:10979",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.11-0:3.11.11-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2024-12-12T00:00:00Z",
        "advisory": "RHSA-2024:10980",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.12-0:3.12.8-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python39:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python39-devel:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2024-12-04T00:00:00Z",
        "advisory": "RHSA-2024:10779",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-69.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2024-12-12T00:00:00Z",
        "advisory": "RHSA-2024:10978",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.12-0:3.12.5-2.el9_5.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2024-12-12T00:00:00Z",
        "advisory": "RHSA-2024:10983",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.21-1.el9_5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2024-12-16T00:00:00Z",
        "advisory": "RHSA-2024:11111",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.11-0:3.11.9-7.el9_5.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2024-12-12T00:00:00Z",
        "advisory": "RHSA-2024:10983",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.21-1.el9_5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2024-12-12T00:00:00Z",
        "advisory": "RHSA-2024:11024",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.9-0:3.9.18-3.el9_4.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2024-12-13T00:00:00Z",
        "advisory": "RHSA-2024:11035",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.12-0:3.12.1-4.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-01-13T00:00:00Z",
        "advisory": "RHSA-2025:0280",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.11-0:3.11.7-1.el9_4.7"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2024-9287\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-9287\nhttps://github.com/python/cpython/issues/124651\nhttps://github.com/python/cpython/pull/124712\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/RSPJ2B5JL22FG3TKUJ7D7DQ4N5JRRBZL/"
    ],
    "name": "CVE-2024-9287",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-09T09:23:18Z",
    "bugzilla": {
      "description": "kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources",
      "id": "2486958",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486958"
    },
    "cvss3": {
      "cvss3_base_score": "8.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-266",
    "details": [
      "Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.",
      "A flaw was found in the Linux kernel on ARM processors. A race condition in Translation Lookaside Buffer Invalidation (TLBI) operations during memory permission changes allows a local attacker to write to memory resources owned by higher privilege levels. This could allow an unprivileged local attacker to gain kernel privileges or a guest VM to escape to the hypervisor, resulting in complete system compromise."
    ],
    "statement": "This is an Important flaw in the Linux kernel on ARM processors, allowing a local unprivileged attacker to achieve privilege escalation to kernel level or a guest virtual machine to escape to the hypervisor. The vulnerability stems from a race condition during Translation Lookaside Buffer Invalidation (TLBI) operations when memory permissions are altered, enabling writes to higher exception level resources.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34911",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "kernel-0:6.12.0-211.30.1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55445",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "kernel-0:6.12.0-55.98.1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36348",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::nfv",
        "package": "kernel-rt-0:4.18.0-553.140.1.rt7.481.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36349",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "kernel-0:4.18.0-553.140.1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47248",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "kernel-0:4.18.0-305.200.1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47248",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "kernel-0:4.18.0-305.200.1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:49033",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "kernel-0:4.18.0-372.204.1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:49033",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "kernel-0:4.18.0-372.204.1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52649",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "kernel-0:4.18.0-477.158.1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52649",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "kernel-0:4.18.0-477.158.1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36018",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "kernel-0:5.14.0-687.22.1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36018",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "kernel-0:5.14.0-687.22.1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-07T00:00:00Z",
        "advisory": "RHSA-2026:51603",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "kernel-0:5.14.0-284.186.1.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-07T00:00:00Z",
        "advisory": "RHSA-2026:51604",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2::nfv",
        "package": "kernel-rt-0:5.14.0-284.186.1.rt14.471.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-07T00:00:00Z",
        "advisory": "RHSA-2026:51746",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "kernel-0:5.14.0-427.143.1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:49031",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "kernel-0:5.14.0-570.131.1.el9_6"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:54205",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202608080425-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:54187",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202608111330-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:54544",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202608111829-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:54553",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202608120446-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54581",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "rhcos-4.20.9.6.202608121719-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54599",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "rhcos-4.21.9.6.202608122143-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:40764",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202607152026-0"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "libkrun",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux for NVIDIA 26",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/a:redhat:enterprise_linux_nvidia:"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-10263\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-10263\nhttps://developer.arm.com/documentation/112137"
    ],
    "name": "CVE-2025-10263",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-09-30T12:18:00Z",
    "bugzilla": {
      "description": "qemu-kvm: VNC WebSocket handshake use-after-free",
      "id": "2401209",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2401209"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-416",
    "details": [
      "A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.",
      "A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication."
    ],
    "statement": "This CVE has been rated as Moderate because it only affects the WebSocket protocol for communication (the VNC raw TCP socket is not affected) and the use of QEMU's in-process WebSocket feature is fairly niche.",
    "acknowledgement": "Red Hat would like to thank Grant Millar (Cylo) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1831",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "qemu-kvm-18:10.0.0-14.el10_1.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5578",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "virt-devel:rhel-8100020251120003312.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5578",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "virt:rhel-8100020251202222937.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18772",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "qemu-kvm-17:10.1.0-17.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22147",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "qemu-kvm-17:6.2.0-11.el9_0.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3077",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "qemu-kvm-17:7.2.0-14.el9_2.24"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-12-17T00:00:00Z",
        "advisory": "RHSA-2025:23228",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "qemu-kvm-17:8.2.0-11.el9_4.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3165",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "qemu-kvm-17:8.2.0-11.el9_4.19"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0326",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202601071926-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0702",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202601120213-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0332",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202601071817-0"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "qemu-kvm",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "qemu-kvm",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "qemu-kvm-ma",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-11234\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-11234"
    ],
    "name": "CVE-2025-11234",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-10-07T22:02:08Z",
    "bugzilla": {
      "description": "binutils: GNU Binutils Linker elflink.c bfd_elf_gc_record_vtentry out-of-bounds",
      "id": "2402425",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402425"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.",
      "A flaw was found in binutils. Processing a specially crafted object file with the ld linker can trigger an out-of-bounds read in the bfd_elf_gc_record_vtentry function in the bfd/elflink.c file due to a missing sanity check, causing a crash and resulting in a denial of service."
    ],
    "statement": "This issue is classified with a low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting the possibility of exploitation. Additionally, this out-of-bounds read is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with ld-new. Furthermore, binutils does not handle privileged operations, meaning that exploitation is unlikely to lead to system compromise or escalation of privileges. Also, the impact is limited to the application itself, without affecting the broader system or network security.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7098",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "binutils-main-2.45.1-5.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-15-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "mingw-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-13-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-13-gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-14-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-14-gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-13-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-13-gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-14-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-15-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mingw-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-11412\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-11412\nhttps://sourceware.org/bugzilla/show_bug.cgi?id=33452\nhttps://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=047435dd988a3975d40c6626a8f739a0b2e154bc\nhttps://vuldb.com/?id.327348"
    ],
    "name": "CVE-2025-11412",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-10-10T22:33:26Z",
    "bugzilla": {
      "description": "wireshark: MONGO dissector infinite loop",
      "id": "2403225",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2403225"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-835",
    "details": [
      "MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service",
      "A flaw was found in Wireshark’s MONGO dissector. When processing certain malformed MONGO packets, the dissector could enter an infinite loop, leading to unbounded CPU consumption. This issue allows an attacker to cause a denial of service by sending a specially crafted packet on the network or by convincing a user to open a malicious capture file."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Out of support scope",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-11626\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-11626\nhttps://gitlab.com/wireshark/wireshark/-/issues/20724\nhttps://www.wireshark.org/security/wnpa-sec-2025-04.html"
    ],
    "name": "CVE-2025-11626",
    "mitigation": {
      "value": "No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-10-16T15:32:11Z",
    "bugzilla": {
      "description": "binutils: GNU Binutils out-of-bounds read",
      "id": "2404481",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2404481"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.",
      "An out of bounds read flaw has been discovered in GNU binutils. The `vfinfo` function in the `ldmisc.c` file. Exploitation of this flaw requires local access and may cause a program crash."
    ],
    "statement": "Red Hat rates this vulnerability as Low as a result of how the GNU Binutils are configured to be used in Red Hat products. When running with default configurations the affected program will have limited privileges and thus the availability impact of this flaw will be restricted.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7098",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "binutils-main-2.45.1-5.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-15-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "mingw-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-13-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-13-gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-14-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-14-gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-13-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-13-gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-14-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-15-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mingw-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-11840\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-11840\nhttps://sourceware.org/bugzilla/attachment.cgi?id=16351\nhttps://sourceware.org/bugzilla/attachment.cgi?id=16357\nhttps://sourceware.org/bugzilla/show_bug.cgi?id=33455\nhttps://vuldb.com/?ctiid.328775\nhttps://vuldb.com/?id.328775\nhttps://vuldb.com/?submit.661281\nhttps://www.gnu.org/"
    ],
    "name": "CVE-2025-11840",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-03T18:55:32Z",
    "bugzilla": {
      "description": "cpython: python: cpython: Quadratic algorithm in xml.dom.minidom leads to denial of service",
      "id": "2418655",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418655"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.",
      "A flaw was found in cpython. This vulnerability allows impacted availability via a quadratic algorithm in `xml.dom.minidom` methods, such as `appendChild()`, when building excessively nested documents due to a dependency on `_clear_id_cache()`"
    ],
    "statement": "This vulnerability is rated Important for Red Hat products as it can lead to a denial of service. The flaw exists in the `xml.dom.minidom` module of cpython, where a quadratic algorithm in methods like `appendChild()` can be triggered when processing excessively nested XML documents. When successfully exploited this may impact the availability of applications utilizing this functionality across affected Red Hat products.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-03T00:00:00Z",
        "advisory": "RHSA-2026:1828",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "python3.12-0:3.12.12-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2233",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "python3.12-0:3.12.9-2.el10_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-01-29T00:00:00Z",
        "advisory": "RHSA-2026:1537",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "python-0:2.7.5-94.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2713",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "python3-0:3.6.8-21.el7_9.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-06T00:00:00Z",
        "advisory": "RHSA-2026:0123",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.12-0:3.12.12-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-27T00:00:00Z",
        "advisory": "RHSA-2026:1374",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.11-0:3.11.13-4.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1631",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-72.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1631",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-72.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1620",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "python3-0:3.6.8-24.el8_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-01-29T00:00:00Z",
        "advisory": "RHSA-2026:1558",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "python3-0:3.6.8-39.el8_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-01-29T00:00:00Z",
        "advisory": "RHSA-2026:1558",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "python3-0:3.6.8-39.el8_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2391",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "python3-0:3.6.8-47.el8_6.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2391",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "python3-0:3.6.8-47.el8_6.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2391",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "python3-0:3.6.8-47.el8_6.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:2084",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "python3.11-0:3.11.2-2.el8_8.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2330",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "python3-0:3.6.8-51.el8_8.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:2084",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "python3.11-0:3.11.2-2.el8_8.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2330",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "python3-0:3.6.8-51.el8_8.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-27T00:00:00Z",
        "advisory": "RHSA-2026:1408",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.12-0:3.12.12-4.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-27T00:00:00Z",
        "advisory": "RHSA-2026:1410",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.11-0:3.11.13-5.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1478",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.25-3.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1478",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.25-3.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2393",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "python3.9-0:3.9.10-4.el9_0.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1922",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "python3.11-0:3.11.2-2.el9_2.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2392",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "python3.9-0:3.9.16-1.el9_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-29T00:00:00Z",
        "advisory": "RHSA-2026:1582",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.12-0:3.12.1-4.el9_4.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1893",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.11-0:3.11.7-1.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2276",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.9-0:3.9.18-3.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-01-29T00:00:00Z",
        "advisory": "RHSA-2026:1583",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "python3.12-0:3.12.9-1.el9_6.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1892",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "python3.11-0:3.11.11-2.el9_6.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2275",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "python3.9-0:3.9.21-2.el9_6.3"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1769104765"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1769111774"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7443",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-13-main-3.13.13-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-11T00:00:00Z",
        "advisory": "RHSA-2026:7661",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-14-main-3.14.4-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8822",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-11-main-3.11.15-4.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8824",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-12-main-3.12.13-3.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2563",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1770646925"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1773670073"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1773672059"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1773670137"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Out of support scope",
        "package_name": "python39-devel:3.9/python39",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Will not fix",
        "package_name": "rhelai1/bootc-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Will not fix",
        "package_name": "rhelai1/bootc-aws-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Will not fix",
        "package_name": "rhelai1/bootc-azure-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Will not fix",
        "package_name": "rhelai1/bootc-azure-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Will not fix",
        "package_name": "rhelai1/bootc-gcp-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Will not fix",
        "package_name": "rhelai1/bootc-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Will not fix",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Will not fix",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Will not fix",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Will not fix",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-12084\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-12084\nhttps://github.com/python/cpython/issues/142145\nhttps://github.com/python/cpython/pull/142146"
    ],
    "name": "CVE-2025-12084",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-15T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A mongoc_bulk_operation_t may read invalid memory if large options are passed."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-12119\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-12119"
    ],
    "name": "CVE-2025-12119",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-04T15:06:00Z",
    "bugzilla": {
      "description": "nfs-utils: rpc.mountd in the nfs-utils privilege escalation",
      "id": "2413081",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2413081"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-279",
    "details": [
      "A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the\nprivileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.",
      "A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the\nprivileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client."
    ],
    "statement": "This MODERATE impact vulnerability in `rpc.mountd` within the `nfs-utils` package allows an authenticated NFSv3 client to bypass configured `root_squash` or `all_squash` restrictions. This enables the client to access subdirectories of an exported NFS share with elevated privileges, regardless of the intended file permissions. Red Hat Enterprise Linux systems configured as NFSv3 servers are affected.",
    "acknowledgement": "Red Hat would like to thank Simon Hall for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-06T00:00:00Z",
        "advisory": "RHSA-2026:3939",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nfs-utils-1:2.8.3-0.el10_1.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3938",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "nfs-utils-1:2.3.3-68.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3940",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nfs-utils-1:2.5.4-38.el9_7.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3940",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "nfs-utils-1:2.5.4-38.el9_7.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-06T00:00:00Z",
        "advisory": "RHSA-2026:3942",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nfs-utils-1:2.5.4-26.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-06T00:00:00Z",
        "advisory": "RHSA-2026:3941",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nfs-utils-1:2.5.4-34.el9_6.3"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:5873",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202603231244-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:5867",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202603242359-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5127",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202603181125-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:5877",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202603251941-0"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5606",
        "cpe": "cpe:/a:redhat:ceph_storage:8::el9",
        "package": "rhceph/rhceph-8-rhel9:1774002867"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "nfs-utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "nfs-utils-lib",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "nfs-utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-12801\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-12801"
    ],
    "name": "CVE-2025-12801",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-11-13T13:00:12Z",
    "bugzilla": {
      "description": "postgresql: CREATE STATISTICS does not check for schema CREATE privilege",
      "id": "2414825",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2414825"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-862",
    "details": [
      "Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema.  A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail.  Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.",
      "A vulnerability has been identified in PostgreSQL’s CREATE STATISTICS command where the database does not check that the user has the required schema CREATE privilege. A table owner user could create a statistics object in any schema, blocking other users who legitimately hold CREATE STATISTICS permissions from creating objects with the same name. This results in a denial-of-service of the statistics creation functionality."
    ],
    "statement": "This issue is rated Low severity by Red Hat Product Security, because exploitation is straightforward once an attacker already holds table-owner privileges. The attack complexity is Low, as no unusual conditions, timing requirements, or unpredictable states are needed; a table owner can simply choose any schema name and intentionally create a statistics object with a conflicting name, which is only trivial to perform and does not require prior knowledge beyond selecting an arbitrary identifier. The availability impact remains Low, since only the creation of a specific statistics object is blocked and normal database operations continue without disruption. There is no confidentiality or integrity impact, and the flaw does not allow privilege escalation. For these reasons, despite a Medium-range CVSS score, the overall impact to Red Hat products is considered Low.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0525",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "postgresql16-0:16.11-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0456",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "postgresql16-0:16.11-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0519",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "postgresql:16-8100020251205224429.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0523",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "postgresql:13-8100020251205223240.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0524",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "postgresql:15-8100020251205224411.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0265",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "postgresql:13-8040020251125121223.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0265",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "postgresql:13-8040020251125121223.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0267",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "postgresql:13-8060020251125073610.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0267",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "postgresql:13-8060020251125073610.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0267",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "postgresql:13-8060020251125073610.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0266",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "postgresql:15-8080020251124123757.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0270",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "postgresql:13-8080020251209095115.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0266",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "postgresql:15-8080020251124123757.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0270",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "postgresql:13-8080020251209095115.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0491",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "postgresql-0:13.23-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0492",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "postgresql:15-9070020251208080035.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0493",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "postgresql:16-9070020251208075121.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0263",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "postgresql-0:13.23-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23022",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "postgresql:15-9020020251119134335.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0455",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "postgresql-0:13.23-1.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-12-04T00:00:00Z",
        "advisory": "RHSA-2025:22728",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "postgresql:15-9040020251126171752.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0262",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "postgresql-0:13.23-1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0264",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "postgresql:16-9040020251119135626.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23023",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "postgresql:15-9060020251205100237.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0268",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "postgresql-0:13.23-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0269",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "postgresql:16-9060020251209100750.rhel9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8756",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "postgresql18-main-18.3-1.2.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "postgresql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "postgresql",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Out of support scope",
        "package_name": "postgresql:12/postgresql",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-12817\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-12817\nhttps://www.postgresql.org/support/security/CVE-2025-12817/"
    ],
    "name": "CVE-2025-12817",
    "mitigation": {
      "value": "No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-11-13T13:00:12Z",
    "bugzilla": {
      "description": "postgresql: libpq: libpq undersizes allocations, via integer wraparound",
      "id": "2414826",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2414826"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes.  This results in a segmentation fault for the application using libpq.  Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.",
      "A vulnerability has been identified in PostgreSQL’s libpq client library, where integer wraparound in several allocation-size calculations allows a peer or input provider to cause an undersized buffer and then write out-of-bounds by hundreds of megabytes. This can lead to a client application segmentation fault or crash when using libpq to connect to a PostgreSQL server."
    ],
    "statement": "This issue is rated Moderate severity by Red Hat Product Security, even though it carries a High CVSS v3.1 score. The flaw resides in the libpq client library and can be triggered when a client receives specially crafted PostgreSQL protocol data that causes an integer wraparound and an out-of-bounds write. The attack complexity is Low because the malformed protocol message is processed immediately during connection, with no timing or environmental conditions required. However, the impact is limited to a denial of service of the client application only. As a result, Red Hat classifies the overall product impact as Moderate, reflecting that the flaw can interrupt client availability.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0525",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "postgresql16-0:16.11-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-01-14T00:00:00Z",
        "advisory": "RHSA-2026:0594",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "libpq-0:16.11-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0456",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "postgresql16-0:16.11-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-01-20T00:00:00Z",
        "advisory": "RHSA-2026:0865",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libpq-0:16.11-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0519",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "postgresql:16-8100020251205224429.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0523",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "postgresql:13-8100020251205223240.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0524",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "postgresql:15-8100020251205224411.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0695",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libpq-0:13.23-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-01-20T00:00:00Z",
        "advisory": "RHSA-2026:0835",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "libpq-0:12.7-1.el8_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0265",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "postgresql:13-8040020251125121223.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-01-19T00:00:00Z",
        "advisory": "RHSA-2026:0744",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libpq-0:13.23-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0265",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "postgresql:13-8040020251125121223.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-01-19T00:00:00Z",
        "advisory": "RHSA-2026:0744",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libpq-0:13.23-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-12-15T00:00:00Z",
        "advisory": "RHSA-2025:23158",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libpq-0:13.23-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0267",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "postgresql:13-8060020251125073610.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-12-15T00:00:00Z",
        "advisory": "RHSA-2025:23158",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "libpq-0:13.23-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0267",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "postgresql:13-8060020251125073610.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-12-15T00:00:00Z",
        "advisory": "RHSA-2025:23158",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "libpq-0:13.23-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0267",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "postgresql:13-8060020251125073610.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2025-12-15T00:00:00Z",
        "advisory": "RHSA-2025:23157",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libpq-0:13.23-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0266",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "postgresql:15-8080020251124123757.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0270",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "postgresql:13-8080020251209095115.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2025-12-15T00:00:00Z",
        "advisory": "RHSA-2025:23157",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libpq-0:13.23-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0266",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "postgresql:15-8080020251124123757.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0270",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "postgresql:13-8080020251209095115.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0458",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libpq-0:13.23-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0491",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "postgresql-0:13.23-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0492",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "postgresql:15-9070020251208080035.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0493",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "postgresql:16-9070020251208075121.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23124",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "libpq-0:13.23-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0263",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "postgresql-0:13.23-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23022",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "postgresql:15-9020020251119134335.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0455",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "postgresql-0:13.23-1.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-01-19T00:00:00Z",
        "advisory": "RHSA-2026:0746",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libpq-0:13.23-1.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-12-04T00:00:00Z",
        "advisory": "RHSA-2025:22728",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "postgresql:15-9040020251126171752.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23123",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "libpq-0:13.23-1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0262",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "postgresql-0:13.23-1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0264",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "postgresql:16-9040020251119135626.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23023",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "postgresql:15-9060020251205100237.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0268",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "postgresql-0:13.23-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0269",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "postgresql:16-9060020251209100750.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-01-19T00:00:00Z",
        "advisory": "RHSA-2026:0745",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libpq-0:13.23-1.el9_6"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1769104765"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8756",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "postgresql18-main-18.3-1.2.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "postgresql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "postgresql",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "postgresql:12/postgresql",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-12818\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-12818\nhttps://www.postgresql.org/support/security/CVE-2025-12818/"
    ],
    "name": "CVE-2025-12818",
    "mitigation": {
      "value": "No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2025-11-21T06:03:52Z",
    "bugzilla": {
      "description": "wireshark: Access of Uninitialized Pointer in Wireshark",
      "id": "2416293",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2416293"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-824",
    "details": [
      "Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service",
      "An uninitialized pointer access has been discovered in Wireshark. An attacker who can provide crafted input may be able to leverage this pointer access weakness to crash the application."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23083",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "wireshark-1:4.4.2-4.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0483",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "wireshark-1:4.4.2-3.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23142",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "wireshark-1:3.4.10-8.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0433",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "wireshark-1:3.4.10-1.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0452",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "wireshark-1:3.4.10-4.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0432",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "wireshark-1:3.4.10-6.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0454",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "wireshark-1:3.4.10-7.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-13499\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-13499\nhttps://gitlab.com/wireshark/wireshark/-/commit/49137f8ce93c9f7ac55b69c8e089ba6a422f633e\nhttps://gitlab.com/wireshark/wireshark/-/issues/20823\nhttps://www.wireshark.org/security/wnpa-sec-2025-06.html"
    ],
    "name": "CVE-2025-13499",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-01T18:02:38Z",
    "bugzilla": {
      "description": "cpython: Excessive read buffering DoS in http.client",
      "id": "2418078",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418078"
    },
    "cvss3": {
      "cvss3_base_score": "6.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.",
      "A flaw was found in the http.client module in the Python standard library. When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This issue allows a malicious server to cause the client to read large amounts of data into memory, potentially causing memory allocations errors, swapping, out-of-memory conditions or even system freezes."
    ],
    "statement": "This issue can only be exploited by Python applications using the http.client.HTTPResponse.read function without the amount parameter, which specifies the read size in bytes. Note that Python libraries may use this function internally and make applications vulnerable. Additionally, vulnerable Python applications must connect to a malicious or compromised server that replies with a very large or crafted Content-Length header to trigger this issue, limiting the exposure of this vulnerability.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-03T00:00:00Z",
        "advisory": "RHSA-2026:1828",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "python3.12-0:3.12.12-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2233",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "python3.12-0:3.12.9-2.el10_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-27T00:00:00Z",
        "advisory": "RHSA-2026:1374",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.11-0:3.11.13-4.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2419",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.12-0:3.12.12-2.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:2084",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "python3.11-0:3.11.2-2.el8_8.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:2084",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "python3.11-0:3.11.2-2.el8_8.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-27T00:00:00Z",
        "advisory": "RHSA-2026:1408",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.12-0:3.12.12-4.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-27T00:00:00Z",
        "advisory": "RHSA-2026:1410",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.11-0:3.11.13-5.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1922",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "python3.11-0:3.11.2-2.el9_2.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1893",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.11-0:3.11.7-1.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3897",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.12-0:3.12.1-4.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1892",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "python3.11-0:3.11.11-2.el9_6.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3900",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "python3.12-0:3.12.9-1.el9_6.5"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8746",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1775680192"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8747",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1775680262"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8748",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1775749857"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1769104765"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7443",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-13-main-3.13.13-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-11T00:00:00Z",
        "advisory": "RHSA-2026:7661",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-14-main-3.14.4-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8822",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-11-main-3.11.15-4.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8824",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-12-main-3.12.13-3.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2563",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1770646925"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2563",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1770808765"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1773670073"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python39-devel:3.9/python39",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python3.9",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-aws-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-gcp-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Will not fix",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Will not fix",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Will not fix",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Will not fix",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/pluginregistry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces-tech-preview/idea-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-13836\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-13836\nhttps://github.com/python/cpython/issues/119451\nhttps://github.com/python/cpython/pull/119454"
    ],
    "name": "CVE-2025-13836",
    "mitigation": {
      "value": "Since this vulnerability is triggered when no read amount is specified and the client defaults to using the potentially malicious Content-Length header, developers can mitigate this issue in their code by always imposing an explicit, safe limit on data reads.\nApplications using the http.client.HTTPResponse.read function directly can ensure that read operations specify a byte limit:\n~~~\n...\nmax_safe_read = 10 * 1024 * 1024\ndata = response.read(max_safe_read)\n...\n~~~",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-01T18:13:32Z",
    "bugzilla": {
      "description": "cpython: Out-of-memory when loading Plist",
      "id": "2418084",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues",
      "A flaw was found in the plistlib module in the Python standard library. The amount of data to read from a Plist file is specified in the file itself. This issue allows a specially crafted Plist file to cause an application to allocate a large amount of memory, potentially resulting in allocations errors, swapping, out-of-memory conditions or even system freezes."
    ],
    "statement": "This issue can only be exploited by Python applications processing malicious or untrusted Plist files, which are not typically done in Linux systems or applications. Furthermore, this flaw can cause only a denial of service with no other security impact. Due to these reasons, this vulnerability has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19064",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "python3.12-0:3.12.13-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10950",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.12-0:3.12.13-2.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19177",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.12-0:3.12.13-2.el9_8"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7443",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-13-main-3.13.13-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-11T00:00:00Z",
        "advisory": "RHSA-2026:7661",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-14-main-3.14.4-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8822",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-11-main-3.11.15-4.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8824",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-12-main-3.12.13-3.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3.11",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python39-devel:3.9/python39",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.9",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-aws-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-azure-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-azure-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-gcp-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/pluginregistry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces-tech-preview/idea-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-13837\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-13837\nhttps://github.com/python/cpython/issues/119342\nhttps://github.com/python/cpython/pull/119343"
    ],
    "name": "CVE-2025-13837",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-03T08:04:54Z",
    "bugzilla": {
      "description": "wireshark: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark",
      "id": "2418572",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418572"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-835",
    "details": [
      "MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service",
      "A flaw was found in the MEGACO dissector in Wireshark. This issue occurs when malformed packets are decoded from a pcap file or the network, causing an infinite loop and resulting in a denial of service."
    ],
    "statement": "This vulnerability will cause a crash in Wireshark with no other security impact. Additionally, this issue can only be exploited when a specially crafted pcap file is processed. For these reasons, this flaw has been rated with a moderate severity.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-13946\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-13946\nhttps://gitlab.com/wireshark/wireshark/-/issues/20884\nhttps://www.wireshark.org/security/wnpa-sec-2025-08.html"
    ],
    "name": "CVE-2025-13946",
    "mitigation": {
      "value": "If the MEGACO protocol dissector is not being used, it can be disabled via the \"Enabled Protocols\" dialog box in the Wireshark GUI application. This will also disable the protocol dissector when using \"tshark\", the command line tool.\nSee the links below for instructions to disable a protocol in Wireshark, specifically the \"Control Protocol Dissection\" section and the \"disabled_protos\" configuration file option.\nhttps://www.wireshark.org/docs/wsug_html_chunked/ChCustProtocolDissectionSection.html\nhttps://www.wireshark.org/docs/wsug_html_chunked/ChAppFilesConfigurationSection.html",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-05T00:00:00Z",
    "bugzilla": {
      "description": "glib: GLib: Buffer underflow in GVariant parser leads to heap corruption",
      "id": "2419093",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2419093"
    },
    "cvss3": {
      "cvss3_base_score": "5.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.",
      "A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings."
    ],
    "statement": "The highest threat is to system availability due to potential application crashes when processing maliciously crafted input strings through GLib's GVariant parser. This issue affects applications that utilize g_variant_parse() on untrusted data, leading to memory corruption and possible denial of service.",
    "acknowledgement": "Red Hat would like to thank Sovereign Tech Resilience program (Sovereign Tech Agency) and treeplus for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15969",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "glib2-0:2.80.4-10.el10_1.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19148",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "glib2-0:2.80.4-12.el10_2.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19567",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "glib2-0:2.80.4-4.el10_0.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19566",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "glib2-0:2.56.1-12.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49512",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "mingw-glib2-0:2.70.1-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15953",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "glib2-0:2.56.4-169.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19565",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "glib2-0:2.56.4-10.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19565",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "glib2-0:2.56.4-10.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19524",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "glib2-0:2.56.4-158.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19524",
        "cpe": "cpe:/o:redhat:rhel_tus:8.6",
        "package": "glib2-0:2.56.4-158.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19524",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.6",
        "package": "glib2-0:2.56.4-158.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19523",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "glib2-0:2.56.4-165.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19523",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "glib2-0:2.56.4-165.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15971",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-18.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19361",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15971",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-18.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19361",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19459",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "glib2-0:2.68.4-5.el9_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19460",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "glib2-0:2.68.4-7.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19452",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "glib2-0:2.68.4-14.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19457",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "glib2-0:2.68.4-16.el9_6.5"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7461",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "glib2-main-2.88.0-1.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22634",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1780420428"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1779798159"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1779798164"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "glycin-loaders",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "loupe",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "papers",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rpm-ostree",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "librsvg2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "librsvg2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-14087\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-14087\nhttps://gitlab.gnome.org/GNOME/glib/-/issues/3834"
    ],
    "name": "CVE-2025-14087",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-05T00:00:00Z",
    "bugzilla": {
      "description": "util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames",
      "id": "2419369",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2419369"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.",
      "A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1696",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "util-linux-0:2.40.2-15.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1852",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "util-linux-0:2.32.1-48.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1852",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "util-linux-0:2.32.1-48.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1913",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "util-linux-0:2.37.4-21.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1913",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "util-linux-0:2.37.4-21.el9_7"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2800",
        "cpe": "cpe:/a:redhat:ceph_storage:7::el9",
        "package": "rhceph/rhceph-7-rhel9:1770632724"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2737",
        "cpe": "cpe:/a:redhat:ceph_storage:8::el9",
        "package": "rhceph/rhceph-8-rhel9:1770630907"
      },
      {
        "product_name": "Red Hat Ceph Storage 9",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3406",
        "cpe": "cpe:/a:redhat:ceph_storage:9::el10",
        "package": "rhceph/rhceph-9-rhel9:1771816028"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7180",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "util-linux-main-2.42-7.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2485",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1770740405"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2563",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1770646925"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1773670073"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1773672059"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1773670137"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "util-linux-ng",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Will not fix",
        "package_name": "util-linux",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-14104\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-14104"
    ],
    "name": "CVE-2025-14104",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-10T03:51:14Z",
    "bugzilla": {
      "description": "php: SQL injection in pdo_firebird via NUL bytes in quoted strings",
      "id": "2468567",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468567"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-89",
    "details": [
      "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.",
      "A flaw was found in PHP. The PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This flaw allows SQL injection when attacker-controlled values are quoted via `PDO::quote()` and embedded in SQL statements."
    ],
    "statement": "This issue can be exploited in applications using the PDO Firebird driver. The application must construct dynamic queries using `PDO::quote()` and the query structure must contain subsequent string boundaries or parameters. This allows an attacker to inject a malicious payload, resulting in the execution of arbitrary database commands. Additionally, the use of `PDO::quote()` for manual concatenation is heavily discouraged and considered a legacy anti-pattern. Modern PHP applications use native prepared statements (`$stmt->execute()`) that are not vulnerable to this issue, limiting its exposure. Due to these reasons, this vulnerability has been rated with an important severity.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "php8.4",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "php:7.4/php",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "php:8.2/php",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "php:8.2/php",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "php:8.3/php",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-14179\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-14179\nhttps://github.com/php/php-src/security/advisories/GHSA-w476-322c-wpvm"
    ],
    "name": "CVE-2025-14179",
    "mitigation": {
      "value": "To mitigate this issue, do not use 'PDO::quote()' for manual query concatenation. Refactor the application to use native parameterized prepared statements. Additionally, implement an input validation mechanism to reject any user-supplied data containing control characters, specifically the NUL byte (\\x00).",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-14T00:00:00Z",
    "bugzilla": {
      "description": "vsftpd: vsftpd: Denial of service via integer overflow in ls command parameter parsing",
      "id": "2419826",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2419826"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.",
      "A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence."
    ],
    "acknowledgement": "Red Hat would like to thank Sankin Nikita Alexeevich for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-01-14T00:00:00Z",
        "advisory": "RHSA-2026:0606",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "vsftpd-0:3.0.5-10.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-16T00:00:00Z",
        "advisory": "RHSA-2026:4553",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vsftpd-0:3.0.5-9.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-14T00:00:00Z",
        "advisory": "RHSA-2026:0608",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vsftpd-0:3.0.3-36.el8_10.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4470",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "vsftpd-0:3.0.3-31.el8_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4477",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "vsftpd-0:3.0.3-33.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4477",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "vsftpd-0:3.0.3-33.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4550",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "vsftpd-0:3.0.3-35.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4550",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "vsftpd-0:3.0.3-35.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4550",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "vsftpd-0:3.0.3-35.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-16T00:00:00Z",
        "advisory": "RHSA-2026:4554",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "vsftpd-0:3.0.3-35.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-16T00:00:00Z",
        "advisory": "RHSA-2026:4554",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "vsftpd-0:3.0.3-35.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-14T00:00:00Z",
        "advisory": "RHSA-2026:0605",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vsftpd-0:3.0.5-6.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4543",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "vsftpd-0:3.0.3-49.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4522",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "vsftpd-0:3.0.5-4.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4525",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "vsftpd-0:3.0.5-5.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4513",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "vsftpd-0:3.0.5-6.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "vsftpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "vsftpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-14242\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-14242"
    ],
    "name": "CVE-2025-14242",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-11T00:00:00Z",
    "bugzilla": {
      "description": "glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow",
      "id": "2421339",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2421339"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.",
      "A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values."
    ],
    "statement": "This vulnerability is rated Moderate for Red Hat products because an integer overflow in GLib's GIO `escape_byte_string()` function can lead to a heap buffer overflow and denial-of-service. This occurs when processing specially crafted file or remote filesystem attribute values, requiring an attacker to provide malicious input.",
    "acknowledgement": "Red Hat would like to thank Codean Labs for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15969",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "glib2-0:2.80.4-10.el10_1.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19148",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "glib2-0:2.80.4-12.el10_2.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19567",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "glib2-0:2.80.4-4.el10_0.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15953",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "glib2-0:2.56.4-169.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19565",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "glib2-0:2.56.4-10.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19565",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "glib2-0:2.56.4-10.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19524",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "glib2-0:2.56.4-158.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19524",
        "cpe": "cpe:/o:redhat:rhel_tus:8.6",
        "package": "glib2-0:2.56.4-158.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19524",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.6",
        "package": "glib2-0:2.56.4-158.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19523",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "glib2-0:2.56.4-165.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19523",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "glib2-0:2.56.4-165.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15971",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-18.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19361",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15971",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-18.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19361",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19459",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "glib2-0:2.68.4-5.el9_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19460",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "glib2-0:2.68.4-7.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19452",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "glib2-0:2.68.4-14.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19457",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "glib2-0:2.68.4-16.el9_6.5"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7461",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "glib2-main-2.88.0-1.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22634",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1780420428"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1779798159"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1779798164"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-14512\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-14512\nhttps://gitlab.gnome.org/GNOME/glib/-/issues/3845"
    ],
    "name": "CVE-2025-14512",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-01-07T00:00:00Z",
    "bugzilla": {
      "description": "curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token",
      "id": "2426407",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2426407"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-201",
    "details": [
      "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
      "A flaw was found in curl. When an OAuth2 (Open Authorization) bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a different scheme like IMAP, LDAP, POP3, or SMTP, curl might incorrectly pass the bearer token to the new target host. This could lead to information disclosure, where sensitive authentication tokens are exposed to unintended recipients."
    ],
    "statement": "This vulnerability is rated Moderate for Red Hat because `curl` might inadvertently pass an OAuth2 bearer token during a cross-protocol redirect from HTTP(S) to IMAP, LDAP, POP3, or SMTP schemes. This could lead to unintended information disclosure if applications using `curl` are configured to perform such redirects with bearer tokens.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6893",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.19.0-3.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/recert-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Fix deferred",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-14524\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-14524"
    ],
    "name": "CVE-2025-14524",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-09T14:26:34Z",
    "bugzilla": {
      "description": "gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification",
      "id": "2423177",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2423177"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-407",
    "details": [
      "A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).",
      "A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs)."
    ],
    "statement": "This vulnerability is rated Moderate for Red Hat. GnuTLS is susceptible to a denial of service attack due to excessive CPU and memory consumption. This occurs when processing specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs) during certificate verification.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3477",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "gnutls-0:3.8.10-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6618",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gnutls-0:3.8.9-9.el10_0.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5585",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5585",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4188",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.3-10.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4188",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.3-10.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6737",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gnutls-0:3.7.6-21.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6738",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gnutls-0:3.8.3-4.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6630",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gnutls-0:3.8.3-6.el9_6.3"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1777325677"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1777325711"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-controller-rhel8:7.13.5-4.1777325710"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1777325680"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1777325709"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1777325680"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1777325708"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7335",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1775740563"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16008",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1778244559"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16009",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1778244531"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8746",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1775680192"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8747",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1775680262"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8748",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1775749857"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5606",
        "cpe": "cpe:/a:redhat:ceph_storage:8::el9",
        "package": "rhceph/rhceph-8-rhel9:1774002867"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7329",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1775668717"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7329",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1775675922"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7477",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gnutls-main-3.8.12-1.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-03-16T00:00:00Z",
        "advisory": "RHSA-2026:4655",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1773685509"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1773670073"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1773672059"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1773668803"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1773670137"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Will not fix",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-14831\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-14831\nhttps://gitlab.com/gnutls/gnutls/-/issues/1773"
    ],
    "name": "CVE-2025-14831",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-01-23T02:49:52Z",
    "bugzilla": {
      "description": "gimp: heap-based buffer overflow via specially crafted PSP file",
      "id": "2432296",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2432296"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-122",
    "details": [
      "GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\nThe specific flaw exists within the parsing of PSP files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28232.",
      "A flaw was found in GIMP. Opening a specially crafted PSP file with GIMP can cause a heap-based buffer overflow due to improper input validation of the length of user-supplied data. An attacker can exploit this vulnerability by convincing a user to open a specially crafted PSP file, resulting in a denial of service or potentially code execution in the context of the current process."
    ],
    "statement": "To exploit this issue, an attacker needs to convince a user to process a specially crafted PSP file with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with an important severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2707",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-1.el9_7.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2969",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gimp-2:2.99.8-3.el9_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2953",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gimp-2:2.99.8-4.el9_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2950",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gimp-2:2.99.8-4.el9_4.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2930",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gimp-2:2.99.8-4.el9_6.5"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "gimp:2.8/gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-15059\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-15059\nhttps://gitlab.gnome.org/GNOME/gimp/-/commit/03575ac8cbb0ef3103b0a15d6598475088dcc15e\nhttps://www.zerodayinitiative.com/advisories/ZDI-25-1196/"
    ],
    "name": "CVE-2025-15059",
    "mitigation": {
      "value": "To mitigate this issue, do not open PSP files from untrusted sources with GIMP.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-01-07T00:00:00Z",
    "bugzilla": {
      "description": "curl: Host verification bypass during SSH transfers",
      "id": "2426409",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2426409"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-358",
    "details": [
      "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
      "A flaw was found in curl. When performing SSH-based transfers using SCP or SFTP, libcurl could mistakenly connect to hosts not listed in the user-specified knownhosts file. This occurs if the host is present in the libssh global knownhosts file, effectively bypassing the intended host verification. This could allow a remote attacker to connect to an untrusted host, potentially leading to information disclosure or man-in-the-middle attacks."
    ],
    "statement": "This vulnerability is rated Important for Red Hat because libcurl, when configured for SSH-based transfers (SCP/SFTP) with a user-specified knownhosts file, may bypass this configuration and accept connections to hosts present in the system-wide libssh global knownhosts file. This could lead to unintended host trust in specific deployment scenarios.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6893",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.19.0-3.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/recert-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Fix deferred",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-15079\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-15079"
    ],
    "name": "CVE-2025-15079",
    "mitigation": {
      "value": "To mitigate this issue, ensure that the system-wide `libssh` global knownhosts file (`/etc/ssh/ssh_known_hosts`) does not contain entries for untrusted hosts. Alternatively, avoid using `libcurl` for SCP or SFTP transfers in environments where strict enforcement of a user-specified knownhosts file is critical and the system-wide knownhosts file cannot be fully controlled. Services relying on `libssh` for host key verification may need to be restarted to apply the changes.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-01-07T00:00:00Z",
    "bugzilla": {
      "description": "curl: libssh key passphrase bypass without agent set",
      "id": "2426410",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2426410"
    },
    "cvss3": {
      "cvss3_base_score": "4.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-305",
    "details": [
      "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
      "A flaw was found in libcurl. When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent."
    ],
    "statement": "This vulnerability is rated Low for Red Hat products. The flaw in libcurl, when built with the libssh backend, allows it to wrongly attempt authentication via a locally running SSH agent during public key authentication for SCP or SFTP transfers. However, successful authentication still requires the SSH agent to possess the correct passphrase.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6893",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.19.0-3.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/recert-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Fix deferred",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-15224\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-15224"
    ],
    "name": "CVE-2025-15224",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Critical",
    "public_date": "2026-01-22T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "9.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-2152\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2152"
    ],
    "name": "CVE-2025-2152",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-04-15T21:00:00Z",
    "bugzilla": {
      "description": "openjdk: Better TLS connection support (Oracle CPU 2025-04)",
      "id": "2359695",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359695"
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-208",
    "details": [
      "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE:8u441, 8u441-perf, 11.0.26, 17.0.14, 21.0.6, 24; Oracle GraalVM for JDK:17.0.14, 21.0.6, 24; Oracle GraalVM Enterprise Edition:20.3.17 and  21.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as  unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)."
    ],
    "statement": "The severity of this vulnerability is considered Moderate rather than Important due to the specific conditions required for exploitation and the complexity involved in executing the attack.",
    "affected_release": [
      {
        "product_name": "Red Hat Build of OpenJDK 11.0.27 ELS",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3850",
        "cpe": "cpe:/a:redhat:openjdk:11",
        "package": "java-11-openjdk-portable"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 11.0.27 ELS",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3849",
        "cpe": "cpe:/a:redhat:openjdk:11::windows",
        "package": "java-11-openjdk-windows"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 17.0.15",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3853",
        "cpe": "cpe:/a:redhat:openjdk:17",
        "package": "java-17-openjdk-portable"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 17.0.15",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3854",
        "cpe": "cpe:/a:redhat:openjdk:17::windows",
        "package": "java-17-openjdk-windows"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 21.0.7",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3856",
        "cpe": "cpe:/a:redhat:openjdk:21",
        "package": "java-21-openjdk-portable"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 21.0.7",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3857",
        "cpe": "cpe:/a:redhat:openjdk:21::windows",
        "package": "java-21-openjdk-windows"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 8u452",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3846",
        "cpe": "cpe:/a:redhat:openjdk:1.8",
        "package": "java-1.8.0-openjdk-portable"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 8u452",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3847",
        "cpe": "cpe:/a:redhat:openjdk:1.8::windows",
        "package": "java-1.8.0-openjdk-windows"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-05-13T00:00:00Z",
        "advisory": "RHSA-2025:7508",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "java-21-openjdk-1:21.0.7.0.6-1.el10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-05-21T00:00:00Z",
        "advisory": "RHSA-2025:8063",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "java-21-ibm-semeru-certified-jdk-1:21.0.7.0.6-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3844",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3855",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-21-openjdk-1:21.0.7.0.6-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-06-03T00:00:00Z",
        "advisory": "RHSA-2025:8431",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::supplementary",
        "package": "java-1.8.0-ibm-1:1.8.0.8.45-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Telecommunications Update Service",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_tus:8.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Telecommunications Update Service",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_tus:8.4",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.4",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_eus:8.8",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_eus:8.8",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3855",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-21-openjdk-1:21.0.7.0.6-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_eus:9.2",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_eus:9.2",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3855",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-21-openjdk-1:21.0.7.0.6-1.el9"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 7",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3848",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el7",
        "package": "java-11-openjdk-1:11.0.27.0.6-1.el7_9"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 8",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3848",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el8",
        "package": "java-11-openjdk-1:11.0.27.0.6-1.el8"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 9",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3848",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el9",
        "package": "java-11-openjdk-1:11.0.27.0.6-1.el9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "java-25-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "java-1.6.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "java-1.7.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "java-1.8.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "java-11-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "java-1.6.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "java-1.7.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Out of support scope",
        "package_name": "java-11-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "java-11-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-21587\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-21587\nhttps://www.oracle.com/security-alerts/cpuapr2025.html#AppendixJAVA"
    ],
    "name": "CVE-2025-21587",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-03-29T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A vulnerability was found in libzvbi up to 0.2.43. It has been classified as problematic. Affected is the function vbi_strndup_iconv_ucs2 of the file src/conv.c. The manipulation of the argument src_length leads to uninitialized pointer. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. The patch is identified as 8def647eea27f7fd7ad33ff79c2d6d3e39948dce. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted very fast and highly professional."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-2173\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2173"
    ],
    "name": "CVE-2025-2173",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-03-29T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A vulnerability was found in libzvbi up to 0.2.43. It has been rated as problematic. Affected by this issue is the function _vbi_strndup_iconv. The manipulation leads to integer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted very fast and highly professional."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-2175\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2175"
    ],
    "name": "CVE-2025-2175",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-03-15T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "3.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-2295\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2295"
    ],
    "name": "CVE-2025-2295",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2024-11-11T00:00:00Z",
    "bugzilla": {
      "description": "cifs-utils: kernel: cifs-utils: cifs.upcall  makes an upcall to the wrong namespace in containerized environments",
      "id": "2352604",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2352604"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-488",
    "details": [
      "A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.",
      "A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache."
    ],
    "statement": "No evidence was found of the possibility of a container escape, restricting the impact to confidentiality. Hence, this flaw is rated with a Moderate impact rating.\nThis flaws affects only the cifs-utils component but requires a two part fix. This is why the kernel component is also listed.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "cifs-utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "cifs-utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "cifs-utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Out of support scope",
        "package_name": "cifs-utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Out of support scope",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "cifs-utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-2312\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2312\nhttps://git.samba.org/?p=cifs-utils.git;a=commit;h=89b679228cc1be9739d54203d28289b03352c174\nhttps://web.git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/fs/smb?id=db363b0a1d9e6b9dc556296f1b1007aeb496a8cf"
    ],
    "name": "CVE-2025-2312",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-03-18T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulation of the argument cmd leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-2361\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2361"
    ],
    "name": "CVE-2025-2361",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-05-29T09:07:34Z",
    "bugzilla": {
      "description": "redis: Redis Stack Buffer Overflow",
      "id": "2369153",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369153"
    },
    "cvss3": {
      "cvss3_base_score": "2.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-805",
    "details": [
      "Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when copying a user-supplied file path into a fixed-size stack buffer. This allows an attacker to overflow the stack and potentially achieve code execution. This issue has been patched in version 8.0.2.",
      "A flaw was found in Redis. Using memcpy with the strlen filepath when copying a user-supplied file path into a fixed-size stack buffer in redis-check-aof results in a stack-based buffer overflow. This flaw allows a local attacker to trigger the overflow by providing a specially crafted file path, allowing potential code execution. The primary consequence is a possible denial of service."
    ],
    "statement": "The availability impact is limited to the instance of Redis and not to the system as a whole.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11401",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "valkey-0:8.0.4-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:12008",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "redis:7-9060020250716081121.9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "aap-cloud-metrics-collector-container",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/ansible-dev-tools-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Not affected",
        "package_name": "rhdh/rhdh-hub-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Not affected",
        "package_name": "rhdh/rhdh-rhel9-operator",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Discovery 1",
        "fix_state": "Not affected",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "redis:6/redis",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "redis",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "valkey",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/instructlab-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-feast-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-feature-server-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-27151\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-27151\nhttps://github.com/redis/redis/commit/643b5db235cb82508e72f11c7b4bbfc7dc39be56\nhttps://github.com/redis/redis/releases/tag/8.0.2\nhttps://github.com/redis/redis/security/advisories/GHSA-5453-q98w-cmvm\nhttps://github.com/valkey-io/valkey/releases"
    ],
    "name": "CVE-2025-27151",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-03-26T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation leads to out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-2750\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2750"
    ],
    "name": "CVE-2025-2750",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-09-05T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation of the argument na leads to out-of-bounds read. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-2751\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2751"
    ],
    "name": "CVE-2025-2751",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-03-26T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-2752\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2752"
    ],
    "name": "CVE-2025-2752",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-03-26T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument src.entries leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-2755\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2755"
    ],
    "name": "CVE-2025-2755",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-03-25T09:31:04Z",
    "bugzilla": {
      "description": "assimp: Open Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection heap-based overflow",
      "id": "2354802",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2354802"
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument tmp leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
      "A flaw was found in the Open Asset Import Library Assimp. This affects the Assimp::AC3DImporter::ConvertObjectSection function of the code/AssetLib/AC/ACLoader.cpp file in the AC3D File Handler component. The manipulation of the tmp argument can lead to a heap-based buffer overflow. It is possible to initiate the attack remotely."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "qt5-qt3d",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-2756\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2756\nhttps://github.com/assimp/assimp/issues/6018\nhttps://github.com/assimp/assimp/issues/6018#issue-2877375815\nhttps://vuldb.com/?ctiid.300861\nhttps://vuldb.com/?id.300861\nhttps://vuldb.com/?submit.517790"
    ],
    "name": "CVE-2025-2756",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-04-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE File Handler. The manipulation of the argument mIndices leads to out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0 is able to address this issue. The patch is named 7c705fde418d68cca4e8eff56be01b2617b0d6fe. It is recommended to apply a patch to fix this issue."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-3015\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-3015"
    ],
    "name": "CVE-2025-3015",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-04-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the component MDL File Handler. The manipulation of the argument mWidth/mHeight leads to resource consumption. The attack can be initiated remotely. Upgrading to version 6.0 is able to address this issue. The name of the patch is 5d2a7482312db2e866439a8c05a07ce1e718bed1. It is recommended to apply a patch to fix this issue."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-3016\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-3016"
    ],
    "name": "CVE-2025-3016",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-03-22T00:00:00Z",
    "bugzilla": {
      "description": "corosync: Stack buffer overflow from 'orf_token_endian_convert'",
      "id": "2354229",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2354229"
    },
    "cvss3": {
      "cvss3_base_score": "6.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-121",
    "details": [
      "Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.",
      "A flaw was found in Corosync. In affected versions, a stack-based buffer overflow may be triggered via a large UDP packet in configurations where encryption is disabled or if an attacker knows the encryption key. This issue can lead to an application crash or other undefined behavior."
    ],
    "statement": "Red Hat believes this vulnerability to be of Moderate impact because successful exploitation requires the attacker to have gained access to the shared secret keys used by the cluster for encrypted communication or for the corosync configuration in the cluster to have encryption and signing disabled, which is a non-standard configuration.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-05-13T00:00:00Z",
        "advisory": "RHSA-2025:7478",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "corosync-0:3.1.9-1.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-05-13T00:00:00Z",
        "advisory": "RHSA-2025:7201",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "corosync-0:3.1.9-2.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "corosync",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "corosync",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-30472\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-30472\nhttps://corosync.org\nhttps://github.com/corosync/corosync/blob/73ba225cc48ebb1903897c792065cb5e876613b0/exec/totemsrp.c#L4677\nhttps://github.com/corosync/corosync/issues/778"
    ],
    "name": "CVE-2025-30472",
    "mitigation": {
      "value": "To mitigate this vulnerability in RHEL, use pcs to ensure that the corosync configuration used in your cluster(s) has encryption enabled (verify that during setup the `--crypto` option's `cipher` and `hash` parameters are not set to `none`).",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-04-15T21:00:00Z",
    "bugzilla": {
      "description": "openjdk: Improve compiler transformations (Oracle CPU 2025-04)",
      "id": "2359694",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359694"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "Vulnerability in Oracle Java SE (component: Compiler).  Supported versions that are affected are Oracle Java SE: 21.0.6, 24; Oracle GraalVM for JDK: 21.0.6 and  24. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE accessible data as well as  unauthorized read access to a subset of Oracle Java SE accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Build of OpenJDK 11.0.27 ELS",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3850",
        "cpe": "cpe:/a:redhat:openjdk:11",
        "package": "java-11-openjdk-portable"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 11.0.27 ELS",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3849",
        "cpe": "cpe:/a:redhat:openjdk:11::windows",
        "package": "java-11-openjdk-windows"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 17.0.15",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3853",
        "cpe": "cpe:/a:redhat:openjdk:17",
        "package": "java-17-openjdk-portable"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 17.0.15",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3854",
        "cpe": "cpe:/a:redhat:openjdk:17::windows",
        "package": "java-17-openjdk-windows"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 21.0.7",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3856",
        "cpe": "cpe:/a:redhat:openjdk:21",
        "package": "java-21-openjdk-portable"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 21.0.7",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3857",
        "cpe": "cpe:/a:redhat:openjdk:21::windows",
        "package": "java-21-openjdk-windows"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 8u452",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3846",
        "cpe": "cpe:/a:redhat:openjdk:1.8",
        "package": "java-1.8.0-openjdk-portable"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 8u452",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3847",
        "cpe": "cpe:/a:redhat:openjdk:1.8::windows",
        "package": "java-1.8.0-openjdk-windows"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-05-13T00:00:00Z",
        "advisory": "RHSA-2025:7508",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "java-21-openjdk-1:21.0.7.0.6-1.el10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3844",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3855",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-21-openjdk-1:21.0.7.0.6-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Telecommunications Update Service",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_tus:8.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Telecommunications Update Service",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_tus:8.4",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.4",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_eus:8.8",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_eus:8.8",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3855",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-21-openjdk-1:21.0.7.0.6-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_eus:9.2",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_eus:9.2",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3855",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-21-openjdk-1:21.0.7.0.6-1.el9"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 7",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3848",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el7",
        "package": "java-11-openjdk-1:11.0.27.0.6-1.el7_9"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 8",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3848",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el8",
        "package": "java-11-openjdk-1:11.0.27.0.6-1.el8"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 9",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3848",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el9",
        "package": "java-11-openjdk-1:11.0.27.0.6-1.el9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "java-21-ibm-semeru-certified-jdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "java-1.6.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "java-1.7.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "java-1.8.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "java-11-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "java-1.6.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "java-1.7.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Out of support scope",
        "package_name": "java-11-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "java-1.8.0-ibm",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "java-11-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-30691\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-30691\nhttps://www.oracle.com/security-alerts/cpuapr2025.html#AppendixJAVA"
    ],
    "name": "CVE-2025-30691",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-04-15T21:00:00Z",
    "bugzilla": {
      "description": "openjdk: Enhance Buffered Image handling (Oracle CPU 2025-04)",
      "id": "2359693",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359693"
    },
    "cvss3": {
      "cvss3_base_score": "5.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-122",
    "details": [
      "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D).  Supported versions that are affected are Oracle Java SE: 8u441, 8u441-perf, 11.0.26, 17.0.14, 21.0.6, 24; Oracle GraalVM for JDK: 17.0.14, 21.0.6, 24; Oracle GraalVM Enterprise Edition: 20.3.17 and  21.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Build of OpenJDK 11.0.27 ELS",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3850",
        "cpe": "cpe:/a:redhat:openjdk:11",
        "package": "java-11-openjdk-portable"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 11.0.27 ELS",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3849",
        "cpe": "cpe:/a:redhat:openjdk:11::windows",
        "package": "java-11-openjdk-windows"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 17.0.15",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3853",
        "cpe": "cpe:/a:redhat:openjdk:17",
        "package": "java-17-openjdk-portable"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 17.0.15",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3854",
        "cpe": "cpe:/a:redhat:openjdk:17::windows",
        "package": "java-17-openjdk-windows"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 21.0.7",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3856",
        "cpe": "cpe:/a:redhat:openjdk:21",
        "package": "java-21-openjdk-portable"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 21.0.7",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3857",
        "cpe": "cpe:/a:redhat:openjdk:21::windows",
        "package": "java-21-openjdk-windows"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 8u452",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3846",
        "cpe": "cpe:/a:redhat:openjdk:1.8",
        "package": "java-1.8.0-openjdk-portable"
      },
      {
        "product_name": "Red Hat Build of OpenJDK 8u452",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3847",
        "cpe": "cpe:/a:redhat:openjdk:1.8::windows",
        "package": "java-1.8.0-openjdk-windows"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-05-13T00:00:00Z",
        "advisory": "RHSA-2025:7508",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "java-21-openjdk-1:21.0.7.0.6-1.el10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-05-21T00:00:00Z",
        "advisory": "RHSA-2025:8063",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "java-21-ibm-semeru-certified-jdk-1:21.0.7.0.6-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3844",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3855",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-21-openjdk-1:21.0.7.0.6-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-06-03T00:00:00Z",
        "advisory": "RHSA-2025:8431",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::supplementary",
        "package": "java-1.8.0-ibm-1:1.8.0.8.45-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Telecommunications Update Service",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_tus:8.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Telecommunications Update Service",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_tus:8.4",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.4",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "java-17-openjdk-1:17.0.15.0.6-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_eus:8.8",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_eus:8.8",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3855",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-21-openjdk-1:21.0.7.0.6-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_eus:9.2",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_eus:9.2",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3845",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.452.b09-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3852",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-17-openjdk-1:17.0.15.0.6-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3855",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-21-openjdk-1:21.0.7.0.6-1.el9"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 7",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3848",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el7",
        "package": "java-11-openjdk-1:11.0.27.0.6-1.el7_9"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 8",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3848",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el8",
        "package": "java-11-openjdk-1:11.0.27.0.6-1.el8"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 9",
        "release_date": "2025-04-16T00:00:00Z",
        "advisory": "RHSA-2025:3848",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el9",
        "package": "java-11-openjdk-1:11.0.27.0.6-1.el9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "java-1.6.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "java-1.7.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "java-1.8.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "java-11-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "java-1.6.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "java-1.7.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Out of support scope",
        "package_name": "java-11-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "java-11-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-30698\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-30698\nhttps://www.oracle.com/security-alerts/cpuapr2025.html#AppendixJAVA"
    ],
    "name": "CVE-2025-30698",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-04-03T13:31:06Z",
    "bugzilla": {
      "description": "assimp: Open Asset Import Library Assimp LWO File LWOAnimation.cpp UpdateAnimRangeSetup heap-based overflow",
      "id": "2357196",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357196"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of the file code/AssetLib/LWO/LWOAnimation.cpp of the component LWO File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.",
      "A flaw has been found in the Open Asset Import Library (assimp). In affected versions, a malformed LWO file may trigger a heap-based buffer overflow, which may lead to an application crash or other undefined behavior."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-08-05T00:00:00Z",
        "advisory": "RHSA-2025:12842",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "qt5-qt3d-0:5.15.9-2.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-09-08T00:00:00Z",
        "advisory": "RHSA-2025:15463",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "qt5-qt3d-0:5.15.2-10.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2025-09-04T00:00:00Z",
        "advisory": "RHSA-2025:15347",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "qt5-qt3d-0:5.15.3-2.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-09-08T00:00:00Z",
        "advisory": "RHSA-2025:15407",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "qt5-qt3d-0:5.15.9-2.el9_4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-3158\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-3158\nhttps://github.com/assimp/assimp/issues/6023\nhttps://github.com/assimp/assimp/issues/6023#issue-2877381000\nhttps://vuldb.com/?ctiid.303104\nhttps://vuldb.com/?id.303104\nhttps://vuldb.com/?submit.542246"
    ],
    "name": "CVE-2025-3158",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-04-03T14:00:17Z",
    "bugzilla": {
      "description": "assimp: Open Asset Import Library Assimp ASE File ASEParser.cpp ParseLV4MeshBonesVertices heap-based overflow",
      "id": "2357216",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357216"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is e8a6286542924e628e02749c4f5ac4f91fdae71b. It is recommended to apply a patch to fix this issue.",
      "A flaw has been found in the Open Asset Import Library (assimp). In affected versions, a malformed ASE file may trigger a heap-based buffer overflow, which may lead to an application crash or other undefined behavior."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-08-05T00:00:00Z",
        "advisory": "RHSA-2025:12842",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "qt5-qt3d-0:5.15.9-2.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-09-08T00:00:00Z",
        "advisory": "RHSA-2025:15463",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "qt5-qt3d-0:5.15.2-10.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2025-09-04T00:00:00Z",
        "advisory": "RHSA-2025:15347",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "qt5-qt3d-0:5.15.3-2.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-09-08T00:00:00Z",
        "advisory": "RHSA-2025:15407",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "qt5-qt3d-0:5.15.9-2.el9_4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-3159\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-3159\nhttps://github.com/assimp/assimp/issues/6024\nhttps://github.com/assimp/assimp/issues/6024#issue-2877382033\nhttps://github.com/assimp/assimp/pull/6051\nhttps://github.com/tellypresence/assimp/commit/e8a6286542924e628e02749c4f5ac4f91fdae71b\nhttps://vuldb.com/?ctiid.303105\nhttps://vuldb.com/?id.303105\nhttps://vuldb.com/?submit.542247"
    ],
    "name": "CVE-2025-3159",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-04-03T14:31:06Z",
    "bugzilla": {
      "description": "assimp: Open Asset Import Library Assimp File SceneCombiner.cpp AddNodeHashes out-of-bounds",
      "id": "2357217",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357217"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the component File Handler. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as a0993658f40d8e13ff5823990c30b43c82a5daf0. It is recommended to apply a patch to fix this issue.",
      "A flaw has been found in the Open Asset Import Library (assimp). In affected versions, a maliciously crafted file may trigger a heap-based buffer overflow, which may lead to an application crash or other undefined behavior."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "qt5-qt3d",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-3160\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-3160\nhttps://github.com/assimp/assimp/commit/a0993658f40d8e13ff5823990c30b43c82a5daf0\nhttps://github.com/assimp/assimp/issues/6025\nhttps://github.com/assimp/assimp/issues/6025#issue-2877385383\nhttps://github.com/assimp/assimp/pull/6049\nhttps://vuldb.com/?ctiid.303106\nhttps://vuldb.com/?id.303106\nhttps://vuldb.com/?submit.542248"
    ],
    "name": "CVE-2025-3160",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-04-04T01:00:12Z",
    "bugzilla": {
      "description": "assimp: Open Asset Import Library Assimp Malformed File MD2Loader.cpp InternReadFile stack-based overflow",
      "id": "2357356",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357356"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD2Importer::InternReadFile in the library code/AssetLib/MD2/MD2Loader.cpp of the component Malformed File Handler. The manipulation of the argument Name leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.",
      "A stack-buffer-overflow vulnerability was found in the Assimp::MD2Importer::InternReadFile function within the Assimp Library. This issue occurs when processing certain malformed files, leading to an out-of-bounds write and potential application crash."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "qt5-qt3d",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-3196\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-3196\nhttps://github.com/assimp/assimp/issues/6069\nhttps://github.com/assimp/assimp/issues/6069#issuecomment-2763273425\nhttps://github.com/assimp/assimp/milestone/11\nhttps://vuldb.com/?ctiid.303150\nhttps://vuldb.com/?id.303150\nhttps://vuldb.com/?submit.545368"
    ],
    "name": "CVE-2025-3196",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2025-07-07T15:22:19Z",
    "bugzilla": {
      "description": "redis: Redis Hyperloglog Out-of-Bounds Write Vulnerability",
      "id": "2376858",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376858"
    },
    "cvss3": {
      "cvss3_base_score": "8.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a stack/heap out of bounds write on hyperloglog operations, potentially leading to remote code execution. The bug likely affects all Redis versions with hyperloglog operations implemented. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19. An additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing hyperloglog operations. This can be done using ACL to restrict HLL commands.",
      "A flaw was found in Redis. This flaw allows an authenticated user to trigger an integer overflow by sending a specially crafted string, resulting in a stack or heap out-of-bounds write during hyperloglog operations. This issue potentially results in remote code execution."
    ],
    "statement": "This flaw can only be exploited by an authenticated attacker when the Redis server has hyperloglog operations implemented, limiting the impact of this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11401",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "valkey-0:8.0.4-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:12006",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "redis:6-8100020250716063446.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12789",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "redis:6-8040020250801055559.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12789",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "redis:6-8040020250801055559.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12769",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "redis:6-8060020250731141235.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12769",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "redis:6-8060020250731141235.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12769",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "redis:6-8060020250731141235.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12768",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "redis:6-8080020250730132007.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12768",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "redis:6-8080020250730132007.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11453",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "redis-0:6.2.19-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:12008",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "redis:7-9060020250716081121.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-07-31T00:00:00Z",
        "advisory": "RHSA-2025:12468",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "redis-0:6.2.6-1.el9_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2025-08-01T00:00:00Z",
        "advisory": "RHSA-2025:12478",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "redis-0:6.2.7-1.el9_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12524",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "redis-0:6.2.7-1.el9_4.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-08-05T00:00:00Z",
        "advisory": "RHSA-2025:12892",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "redis:7-9040020250730125543.9"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-08-27T00:00:00Z",
        "advisory": "RHBA-2025:14521",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/clair-rhel8:v3.13.8-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-08-27T00:00:00Z",
        "advisory": "RHBA-2025:14521",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-bridge-operator-bundle:v3.13.8-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-08-27T00:00:00Z",
        "advisory": "RHBA-2025:14521",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-bridge-operator-rhel8:v3.13.8-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-08-27T00:00:00Z",
        "advisory": "RHBA-2025:14521",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-builder-qemu-rhcos-rhel8:v3.13.8-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-08-27T00:00:00Z",
        "advisory": "RHBA-2025:14521",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-builder-rhel8:v3.13.8-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-08-27T00:00:00Z",
        "advisory": "RHBA-2025:14521",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-container-security-operator-bundle:v3.13.8-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-08-27T00:00:00Z",
        "advisory": "RHBA-2025:14521",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-container-security-operator-rhel8:v3.13.8-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-08-27T00:00:00Z",
        "advisory": "RHBA-2025:14521",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-operator-bundle:v3.13.8-13"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-08-27T00:00:00Z",
        "advisory": "RHBA-2025:14521",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-operator-rhel8:v3.13.8-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-08-27T00:00:00Z",
        "advisory": "RHBA-2025:14521",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-rhel8:v3.13.8-4"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-02T00:00:00Z",
        "advisory": "RHBA-2025:14522",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/clair-rhel8:v3.11.13-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-02T00:00:00Z",
        "advisory": "RHBA-2025:14522",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-bridge-operator-bundle:v3.11.13-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-02T00:00:00Z",
        "advisory": "RHBA-2025:14522",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-bridge-operator-rhel8:v3.11.13-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-02T00:00:00Z",
        "advisory": "RHBA-2025:14522",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-builder-qemu-rhcos-rhel8:v3.11.13-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-02T00:00:00Z",
        "advisory": "RHBA-2025:14522",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-builder-rhel8:v3.11.13-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-02T00:00:00Z",
        "advisory": "RHBA-2025:14522",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-container-security-operator-bundle:v3.11.13-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-02T00:00:00Z",
        "advisory": "RHBA-2025:14522",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-container-security-operator-rhel8:v3.11.13-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-02T00:00:00Z",
        "advisory": "RHBA-2025:14522",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-operator-bundle:v3.11.13-14"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-02T00:00:00Z",
        "advisory": "RHBA-2025:14522",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-operator-rhel8:v3.11.13-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-02T00:00:00Z",
        "advisory": "RHBA-2025:14522",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-rhel8:v3.11.13-6"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-23T00:00:00Z",
        "advisory": "RHBA-2025:16395",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/clair-rhel8:v3.12.12-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-23T00:00:00Z",
        "advisory": "RHBA-2025:16395",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-bridge-operator-bundle:v3.12.12-4"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-23T00:00:00Z",
        "advisory": "RHBA-2025:16395",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-bridge-operator-rhel8:v3.12.12-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-23T00:00:00Z",
        "advisory": "RHBA-2025:16395",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-builder-qemu-rhcos-rhel8:v3.12.12-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-23T00:00:00Z",
        "advisory": "RHBA-2025:16395",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-builder-rhel8:v3.12.12-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-23T00:00:00Z",
        "advisory": "RHBA-2025:16395",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-container-security-operator-bundle:v3.12.12-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-23T00:00:00Z",
        "advisory": "RHBA-2025:16395",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-container-security-operator-rhel8:v3.12.12-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-23T00:00:00Z",
        "advisory": "RHBA-2025:16395",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-operator-bundle:v3.12.12-18"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-23T00:00:00Z",
        "advisory": "RHBA-2025:16395",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-operator-rhel8:v3.12.12-3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "release_date": "2025-09-23T00:00:00Z",
        "advisory": "RHBA-2025:16395",
        "cpe": "cpe:/a:redhat:quay:3::el8",
        "package": "quay/quay-rhel8:v3.12.12-11"
      }
    ],
    "package_state": [
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/aap-cloud-metrics-collector-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/ansible-dev-tools-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Not affected",
        "package_name": "rhdh/rhdh-hub-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Not affected",
        "package_name": "rhdh/rhdh-rhel9-operator",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Discovery 1",
        "fix_state": "Not affected",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "valkey",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-aws-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-gcp-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-intel-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/gemma-2-9b-it",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/gemma-2-9b-it-fp8",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/granite-3.1-8b-lab-v2.1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/granite-3.1-8b-starter-v2.1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/instructlab-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/instructlab-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-gemma-2-9b-it",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-gemma-2-9b-it-fp8",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-granite-3-1-8b-lab-v2-1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-granite-3-1-8b-starter-v2-1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-argoexec-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-feast-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-launcher-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-32023\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-32023\nhttps://github.com/redis/redis/commit/50188747cbfe43528d2719399a2a3c9599169445\nhttps://github.com/redis/redis/releases/tag/6.2.19\nhttps://github.com/redis/redis/releases/tag/7.2.10\nhttps://github.com/redis/redis/releases/tag/7.4.5\nhttps://github.com/redis/redis/releases/tag/8.0.3\nhttps://github.com/redis/redis/security/advisories/GHSA-rp2m-q4j6-gr43"
    ],
    "name": "CVE-2025-32023",
    "mitigation": {
      "value": "Prevent users, specially unprivileged or untrusted users, to execute hyperloglog operations by using ACL to restrict hyperloglog commands.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-04-03T00:00:00Z",
    "bugzilla": {
      "description": "libsoup: Denial of Service attack to websocket server",
      "id": "2357066",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357066"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS).",
      "A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-05-26T00:00:00Z",
        "advisory": "RHSA-2025:8128",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "libsoup3-0:3.6.5-3.el10_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2025-11-18T00:00:00Z",
        "advisory": "RHSA-2025:21657",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libsoup-0:2.62.2-9.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2025-06-17T00:00:00Z",
        "advisory": "RHSA-2025:9179",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libsoup-0:2.62.2-6.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-05-26T00:00:00Z",
        "advisory": "RHSA-2025:8132",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libsoup-0:2.62.3-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-05-26T00:00:00Z",
        "advisory": "RHSA-2025:8132",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "libsoup-0:2.62.3-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2025-06-04T00:00:00Z",
        "advisory": "RHSA-2025:8480",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "libsoup-0:2.62.3-1.el8_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-06-09T00:00:00Z",
        "advisory": "RHSA-2025:8663",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libsoup-0:2.62.3-2.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-06-04T00:00:00Z",
        "advisory": "RHSA-2025:8482",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libsoup-0:2.62.3-2.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-06-04T00:00:00Z",
        "advisory": "RHSA-2025:8482",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "libsoup-0:2.62.3-2.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-06-04T00:00:00Z",
        "advisory": "RHSA-2025:8482",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "libsoup-0:2.62.3-2.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Extended Update Support",
        "release_date": "2025-05-28T00:00:00Z",
        "advisory": "RHSA-2025:8252",
        "cpe": "cpe:/a:redhat:rhel_eus:8.8",
        "package": "libsoup-0:2.62.3-3.el8_8.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-05-26T00:00:00Z",
        "advisory": "RHSA-2025:8126",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libsoup-0:2.72.0-10.el9_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-06-04T00:00:00Z",
        "advisory": "RHSA-2025:8481",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "libsoup-0:2.72.0-8.el9_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Extended Update Support",
        "release_date": "2025-05-26T00:00:00Z",
        "advisory": "RHSA-2025:8140",
        "cpe": "cpe:/a:redhat:rhel_eus:9.2",
        "package": "libsoup-0:2.72.0-8.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-05-26T00:00:00Z",
        "advisory": "RHSA-2025:8139",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "libsoup-0:2.72.0-8.el9_4.5"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-32049\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-32049\nhttps://gitlab.gnome.org/GNOME/libsoup/-/issues/390\nhttps://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/408"
    ],
    "name": "CVE-2025-32049",
    "mitigation": {
      "value": "No mitigation is currently available for this vulnerability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-12T16:35:09Z",
    "bugzilla": {
      "description": "kernel: Kernel: Information disclosure via shared microarchitectural predictor state in Intel(R) Processors",
      "id": "2476541",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476541"
    },
    "cvss3": {
      "cvss3_base_score": "5.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-1037",
    "details": [
      "Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Processors within VMX non-root (guest) operation may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.",
      "A flaw was found in the kernel. This vulnerability, affecting some Intel(R) Processors, involves shared microarchitectural predictor state that influences transient execution within VMX non-root (guest) operation. An unprivileged software adversary with an authenticated user can exploit this locally to disclose sensitive information. This high-complexity attack requires no user interaction and can lead to significant data exposure."
    ],
    "statement": "This Moderate impact information disclosure flaw affects Intel processors in virtualized environments utilizing VMX non-root (guest) operation. An authenticated, unprivileged local attacker could exploit shared microarchitectural predictor states to transiently execute code and potentially expose sensitive data. The high complexity of the attack reduces its immediate threat.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "microcode_ctl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "microcode_ctl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "microcode_ctl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "microcode_ctl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "microcode_ctl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-35979\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-35979\nhttps://intel.com/content/www/us/en/security-center/advisory/intel-sa-01420.html"
    ],
    "name": "CVE-2025-35979",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2025-09-19T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-3770\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-3770"
    ],
    "name": "CVE-2025-3770",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2025-06-03T12:59:02Z",
    "bugzilla": {
      "description": "cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory",
      "id": "2372426",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2372426"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-22",
    "details": [
      "Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.",
      "A flaw was found in the Python tarfile module. This vulnerability allows attackers to bypass extraction filters, enabling symlink targets to escape the destination directory and allowing unauthorized modification of file metadata via the use of TarFile.extract() or TarFile.extractall() with the filter= parameter set to \"data\" or \"tar\"."
    ],
    "statement": "Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide \"symlinks\" to the main python3 component, which provides the actual interpreter of the Python programming language.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10140",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "python3.12-0:3.12.9-2.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10026",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.11-0:3.11.13-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10031",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.12-0:3.12.11-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10128",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-70.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python39:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python39-devel:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "python39:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "python39-devel:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10128",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-70.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Extended Update Support Long-Life Add-On",
        "release_date": "2025-07-08T00:00:00Z",
        "advisory": "RHSA-2025:10602",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.8",
        "package": "python3-0:3.6.8-51.el8_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2025-07-08T00:00:00Z",
        "advisory": "RHSA-2025:10602",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "python3-0:3.6.8-51.el8_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2025-07-08T00:00:00Z",
        "advisory": "RHSA-2025:10602",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "python3-0:3.6.8-51.el8_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10136",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.21-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10148",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.11-0:3.11.11-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-02T00:00:00Z",
        "advisory": "RHSA-2025:10189",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.12-0:3.12.9-1.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10136",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.21-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10028",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.12-0:3.12.1-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10399",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.9-0:3.9.18-3.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-06-30T00:00:00Z",
        "advisory": "RHSA-2025:9918",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.11-0:3.11.7-1.el9_4.8"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1752066672"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1752065732"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-controller-rhel8:7.13.5-4.1752065732"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1752065737"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1752065731"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-operator-bundle:7.13.5-25"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1752065736"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-rhel8-operator:7.13.5-2.1752065733"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11386",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1752065755"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-management-console-rhel8:1.36.0-9"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-operator-bundle:1.36.0-12"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-rhel8-operator:1.36.0-18"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7"
      },
      {
        "product_name": "cert-manager operator for Red Hat OpenShift 1.16",
        "release_date": "2025-10-16T00:00:00Z",
        "advisory": "RHSA-2025:18219",
        "cpe": "cpe:/a:redhat:cert_manager:1.16::el9",
        "package": "cert-manager/jetstack-cert-manager-rhel9:v1.16.5-1760515757"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2025-08-06T00:00:00Z",
        "advisory": "RHSA-2025:13267",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:2.0.1-1754478727"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-4138\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-4138\nhttps://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f\nhttps://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a\nhttps://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a\nhttps://github.com/python/cpython/issues/135034\nhttps://github.com/python/cpython/pull/135037\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"
    ],
    "name": "CVE-2025-4138",
    "mitigation": {
      "value": "Red Hat recommends upgrading to a fixed release of Python as soon as one is available. This vulnerability can be mitigated by rejecting links inside tarfiles that use relative references to the parent directory. The upstream advisory provides this example code:\n'''\n# Avoid insecure segments in link names.\nfor member in tar.getmembers():\nif not member.islnk():\ncontinue\nif os.pardir in os.path.split(member.linkname):\nraise OSError(\"Tarfile with insecure segment ('..') in linkname\")\n# Now safe to extract members with the data filter.\ntar.extractall(filter=\"data\")\n'''",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-07-28T17:46:46Z",
    "bugzilla": {
      "description": "hplip: HP Linux Imaging and Printing Software - Use of DSA Key",
      "id": "2384011",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2384011"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:L",
      "status": "draft"
    },
    "cwe": "CWE-347",
    "details": [
      "A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak code signing key, Digital Signature Algorithm (DSA).",
      "A flaw was found in the HP Linux Imaging and Printing Software (HPLIP). This vulnerability is due to the use of a weak Digital Signature Algorithm (DSA) for code signing. A remote attacker could exploit this weakness to forge signatures, potentially leading to the execution of unauthorized code or tampering with the software. This could compromise the integrity and confidentiality of the affected system."
    ],
    "statement": "This flaw relates to the method with which HP distributes the their HP imaging and printing software. Users who install this product via Red Hat package management tools are not affected.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "hplip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "hplip",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "hplip",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "hplip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "hplip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-43023\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-43023\nhttps://support.hp.com/us-en/document/ish_12804224-12804228-16/hpsbpi04033\nhttps://www.openwall.com/lists/oss-security/2025/08/22/4"
    ],
    "name": "CVE-2025-43023",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-06-03T12:58:57Z",
    "bugzilla": {
      "description": "cpython: python: Extraction filter bypass for linking outside extraction directory",
      "id": "2370014",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370014"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-22",
    "details": [
      "Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.",
      "A flaw was found in CPython's tarfile module. This vulnerability allows bypassing of extraction filters, enabling symlink traversal outside the intended extraction directory and potential modification of file metadata via malicious tar archives using TarFile.extractall() or TarFile.extract() with the filter=\"data\" or filter=\"tar\" parameters. This issue leads to potentially overwriting or modifying system files and metadata."
    ],
    "statement": "The severity of this vulnerability was lowered due to the fact that successful exploitation requires the attacker to convince a privileged user or process to extract a malicious tar file. Since tar file extraction typically occurs in trusted contexts or with elevated privileges, the impact is reduced by the requirement of this access.\nVersions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide \"symlinks\" to the main python3 component, which provides the actual interpreter of the Python programming language.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10140",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "python3.12-0:3.12.9-2.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10026",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.11-0:3.11.13-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10031",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.12-0:3.12.11-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10128",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-70.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python39:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python39-devel:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10128",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-70.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Extended Update Support Long-Life Add-On",
        "release_date": "2025-07-08T00:00:00Z",
        "advisory": "RHSA-2025:10602",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.8",
        "package": "python3-0:3.6.8-51.el8_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2025-07-08T00:00:00Z",
        "advisory": "RHSA-2025:10602",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "python3-0:3.6.8-51.el8_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2025-07-08T00:00:00Z",
        "advisory": "RHSA-2025:10602",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "python3-0:3.6.8-51.el8_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10136",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.21-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10148",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.11-0:3.11.11-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-02T00:00:00Z",
        "advisory": "RHSA-2025:10189",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.12-0:3.12.9-1.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10136",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.21-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10028",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.12-0:3.12.1-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10399",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.9-0:3.9.18-3.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-06-30T00:00:00Z",
        "advisory": "RHSA-2025:9918",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.11-0:3.11.7-1.el9_4.8"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2025-08-06T00:00:00Z",
        "advisory": "RHSA-2025:13267",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:2.0.1-1754478727"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54760",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1786638573"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-10T00:00:00Z",
        "advisory": "RHSA-2026:38017",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-12-main-3.12.13-3.5.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-10T00:00:00Z",
        "advisory": "RHSA-2026:38090",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-13-main-3.13.14-1.4.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-10T00:00:00Z",
        "advisory": "RHSA-2026:38091",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-14-main-3.14.6-1.4.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "python38:3.8/python38",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-aws-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-gcp-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-intel-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/granite-3.1-8b-lab-v2.1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/granite-3.1-8b-starter-v2.1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/instructlab-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/instructlab-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-granite-3-1-8b-lab-v2-1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-granite-3-1-8b-starter-v2-1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-4330\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-4330\nhttps://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f\nhttps://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a\nhttps://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a\nhttps://github.com/python/cpython/issues/135034\nhttps://github.com/python/cpython/pull/135037\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"
    ],
    "name": "CVE-2025-4330",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-06-03T12:59:06Z",
    "bugzilla": {
      "description": "cpython: Tarfile extracts filtered members when errorlevel=0",
      "id": "2370010",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370010"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-706",
    "details": [
      "When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.",
      "A flaw was found in CPython's tarfile module. This vulnerability allows unauthorized file extraction via crafted tar archives when TarFile.errorlevel=0, bypassing expected filtering mechanisms."
    ],
    "statement": "The severity of this vulnerability was lowered due to the fact that successful exploitation requires the attacker to convince a privileged user or process to extract a malicious tar file. Since tar file extraction typically occurs in trusted contexts or with elevated privileges, the impact is reduced by the requirement of such access.\nVersions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide \"symlinks\" to the main python3 component, which provides the actual interpreter of the Python programming language.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10140",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "python3.12-0:3.12.9-2.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10026",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.11-0:3.11.13-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10031",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.12-0:3.12.11-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10128",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-70.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python39:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python39-devel:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "python39:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "python39-devel:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10128",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-70.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10484",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "python3-0:3.6.8-47.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Extended Update Support Long-Life Add-On",
        "release_date": "2025-07-08T00:00:00Z",
        "advisory": "RHSA-2025:10602",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.8",
        "package": "python3-0:3.6.8-51.el8_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2025-07-08T00:00:00Z",
        "advisory": "RHSA-2025:10602",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "python3-0:3.6.8-51.el8_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2025-07-08T00:00:00Z",
        "advisory": "RHSA-2025:10602",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "python3-0:3.6.8-51.el8_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10136",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.21-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10148",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.11-0:3.11.11-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-02T00:00:00Z",
        "advisory": "RHSA-2025:10189",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.12-0:3.12.9-1.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10136",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.21-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:10028",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.12-0:3.12.1-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10399",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.9-0:3.9.18-3.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-06-30T00:00:00Z",
        "advisory": "RHSA-2025:9918",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.11-0:3.11.7-1.el9_4.8"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2025-08-06T00:00:00Z",
        "advisory": "RHSA-2025:13267",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:2.0.1-1754478727"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-aws-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-gcp-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-intel-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/granite-3.1-8b-lab-v2.1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/granite-3.1-8b-starter-v2.1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/instructlab-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/instructlab-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-granite-3-1-8b-lab-v2-1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-granite-3-1-8b-starter-v2-1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-4435\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-4435\nhttps://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a\nhttps://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a\nhttps://github.com/python/cpython/issues/135034\nhttps://github.com/python/cpython/pull/135037\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"
    ],
    "name": "CVE-2025-4435",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-06-11T16:42:53Z",
    "bugzilla": {
      "description": "net/http: Sensitive headers not cleared on cross-origin redirect in net/http",
      "id": "2373305",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373305"
    },
    "cvss3": {
      "cvss3_base_score": "6.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N",
      "status": "verified"
    },
    "details": [
      "Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.",
      "A flaw was found in net/http. Handling Proxy-Authorization and Proxy-Authenticate headers during cross-origin redirects allows these headers to be inadvertently forwarded, potentially exposing sensitive authentication credentials. This flaw allows a network-based attacker to manipulate redirect responses, unintentionally exposing authentication details to unauthorized parties."
    ],
    "statement": "The issue is rated as Moderate because while it can lead to a significant compromise of confidentiality, the attack complexity is high. Successful exploitation requires a specific set of circumstances, including the use of a proxy that relies on these headers for authentication and a user being enticed to interact with a malicious URL. The vulnerability does not allow for arbitrary code execution or a direct compromise of system integrity or availability.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-07-09T00:00:00Z",
        "advisory": "RHSA-2025:10677",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "golang-0:1.24.4-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-09-23T00:00:00Z",
        "advisory": "RHSA-2025:16432",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "opentelemetry-collector-0:0.127.0-3.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-09T00:00:00Z",
        "advisory": "RHSA-2025:10672",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "go-toolset:rhel8-8100020250705224704.a3795dee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-09T00:00:00Z",
        "advisory": "RHSA-2025:10676",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "golang-0:1.24.4-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-09-16T00:00:00Z",
        "advisory": "RHSA-2025:15887",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "opentelemetry-collector-0:0.127.0-2.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-09-08T00:00:00Z",
        "advisory": "RHSA-2025:15406",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "opentelemetry-collector-0:0.127.0-2.el9_4"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.6.0",
        "release_date": "2025-07-09T00:00:00Z",
        "advisory": "RHSA-2025:10735",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.6::el8",
        "package": "rhosdt/opentelemetry-collector-rhel8:rhosdt-3.6-1752046452"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.6.0",
        "release_date": "2025-07-09T00:00:00Z",
        "advisory": "RHSA-2025:10735",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.6::el8",
        "package": "rhosdt/opentelemetry-rhel8-operator:rhosdt-3.6-1752046437"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.6.0",
        "release_date": "2025-07-09T00:00:00Z",
        "advisory": "RHSA-2025:10735",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.6::el8",
        "package": "rhosdt/opentelemetry-target-allocator-rhel8:rhosdt-3.6-1752046439"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.6.0",
        "release_date": "2025-07-10T00:00:00Z",
        "advisory": "RHSA-2025:10823",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.6::el8",
        "package": "rhosdt/tempo-gateway-opa-rhel8:rhosdt-3.6-1752070865"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.6.0",
        "release_date": "2025-07-10T00:00:00Z",
        "advisory": "RHSA-2025:10823",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.6::el8",
        "package": "rhosdt/tempo-gateway-rhel8:rhosdt-3.6-1752070873"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.6.0",
        "release_date": "2025-07-10T00:00:00Z",
        "advisory": "RHSA-2025:10823",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.6::el8",
        "package": "rhosdt/tempo-jaeger-query-rhel8:rhosdt-3.6-1751993590"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.6.0",
        "release_date": "2025-07-10T00:00:00Z",
        "advisory": "RHSA-2025:10823",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.6::el8",
        "package": "rhosdt/tempo-query-rhel8:rhosdt-3.6-1752070827"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.6.0",
        "release_date": "2025-07-10T00:00:00Z",
        "advisory": "RHSA-2025:10823",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.6::el8",
        "package": "rhosdt/tempo-rhel8:rhosdt-3.6-1752070833"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.6.0",
        "release_date": "2025-07-10T00:00:00Z",
        "advisory": "RHSA-2025:10823",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.6::el8",
        "package": "rhosdt/tempo-rhel8-operator:rhosdt-3.6-1752070866"
      }
    ],
    "package_state": [
      {
        "product_name": "Cryostat 4",
        "fix_state": "Fix deferred",
        "package_name": "cryostat/cryostat-storage-rhel9",
        "cpe": "cpe:/a:redhat:cryostat:4"
      },
      {
        "product_name": "Custom Metric Autoscaler operator for Red Hat Openshift",
        "fix_state": "Fix deferred",
        "package_name": "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
      },
      {
        "product_name": "Deployment Validation Operator",
        "fix_state": "Fix deferred",
        "package_name": "dvo/deployment-validation-rhel8-operator",
        "cpe": "cpe:/a:redhat:deployment_validator_operator"
      },
      {
        "product_name": "Fence Agents Remediation Operator",
        "fix_state": "Fix deferred",
        "package_name": "workload-availability/fence-agents-remediation-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_far:0"
      },
      {
        "product_name": "Gatekeeper 3",
        "fix_state": "Fix deferred",
        "package_name": "gatekeeper/gatekeeper-rhel9",
        "cpe": "cpe:/a:redhat:gatekeeper:3"
      },
      {
        "product_name": "Kube Descheduler Operator",
        "fix_state": "Fix deferred",
        "package_name": "kube-descheduler-operator/descheduler-rhel9",
        "cpe": "cpe:/a:redhat:kube_descheduler_operator:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Fix deferred",
        "package_name": "lvms4/lvms-rhel9-operator",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Fix deferred",
        "package_name": "workload-availability/machine-deletion-remediation-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "Migration Toolkit for Applications 7",
        "fix_state": "Fix deferred",
        "package_name": "mta/mta-cli-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Fix deferred",
        "package_name": "rhmtc/openshift-migration-registry-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Fix deferred",
        "package_name": "migration-toolkit-virtualization/mtv-api-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Fix deferred",
        "package_name": "multicluster-engine/hive-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Fix deferred",
        "package_name": "multicluster-engine/hive-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Fix deferred",
        "package_name": "multicluster-globalhub/multicluster-globalhub-agent-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Fix deferred",
        "package_name": "workload-availability/node-healthcheck-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "Node Maintenance Operator",
        "fix_state": "Fix deferred",
        "package_name": "container-native-virtualization/node-maintenance-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nmo:5"
      },
      {
        "product_name": "Node Maintenance Operator",
        "fix_state": "Fix deferred",
        "package_name": "workload-availability/node-maintenance-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nmo:5"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Fix deferred",
        "package_name": "oadp/oadp-velero-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Fix deferred",
        "package_name": "helm",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Fix deferred",
        "package_name": "openshift-pipelines-client",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Run Once Duration Override Operator",
        "fix_state": "Fix deferred",
        "package_name": "run-once-duration-override-operator/run-once-duration-override-rhel9",
        "cpe": "cpe:/a:redhat:run_once_duration_override_operator:1"
      },
      {
        "product_name": "OpenShift Secondary Scheduler Operator",
        "fix_state": "Fix deferred",
        "package_name": "openshift-secondary-scheduler-operator/secondary-scheduler-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_secondary_scheduler:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "kn-workflow-plugin",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/logic-rhel8-operator",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1-tech-preview/logic-rhel8-operator",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-istio-cni-container",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Power monitoring for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-power-monitoring/kepler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_power_monitoring"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-tech-preview/authorino-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "rhcl-1/authorino-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "flightctl",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "rhacm2/subctl-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Fix deferred",
        "package_name": "advanced-cluster-security/rhacs-main-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "aap-cloud-ui-container",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-gateway-proxy",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-gateway-proxy-openssl30",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-gateway-proxy-openssl32",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "python3.11-galaxy-ng",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "receptor",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat build of Apache Camel - HawtIO 4",
        "fix_state": "Fix deferred",
        "package_name": "hawtio-operator-container",
        "cpe": "cpe:/a:redhat:apache_camel_hawtio:4"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Fix deferred",
        "package_name": "ceph",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Fix deferred",
        "package_name": "ceph",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/snmp-notifier-rhel8",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/snmp-notifier-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Fix deferred",
        "package_name": "ceph",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Certification for Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "redhat-certification-preflight",
        "cpe": "cpe:/a:redhat:certifications:1::el8"
      },
      {
        "product_name": "Red Hat Certification Program for Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "redhat-certification-preflight",
        "cpe": "cpe:/a:redhat:certifications:9"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Fix deferred",
        "package_name": "3scale-tech-preview/authorino-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Fix deferred",
        "package_name": "rhcl-1/authorino-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Fix deferred",
        "package_name": "flightctl",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "butane",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "delve",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "git-lfs",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "golang-github-openprinting-ipp-usb",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "grafana-pcp",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gvisor-tap-vsock",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "ignition",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "osbuild-composer",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhc",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhc-worker-playbook",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "yggdrasil",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "host-metering",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "rhc",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "rhc-worker-script",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "container-tools:rhel8/buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "container-tools:rhel8/conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "container-tools:rhel8/containernetworking-plugins",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "container-tools:rhel8/podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "container-tools:rhel8/skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "container-tools:rhel8/toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "git-lfs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "grafana-pcp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "osbuild-composer",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "rhc",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "weldr-client",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "butane",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "containernetworking-plugins",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "git-lfs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "grafana-pcp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gvisor-tap-vsock",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ignition",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "osbuild-composer",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "weldr-client",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "golang",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhods/odh-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "butane",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "conmon",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "conmon-rs",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "containernetworking-plugins",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "cri-o",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "cri-tools",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "golang-github-prometheus-promu",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "ignition",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "microshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift-clients",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift-kuryr",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "ose-aws-ecr-image-credential-provider",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "ose-azure-acr-image-credential-provider",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "ose-gcp-gcr-image-credential-provider",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "podman",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "skopeo",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Fix deferred",
        "package_name": "odf4/odf-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/udi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Fix deferred",
        "package_name": "openshift-gitops-1/gitops-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift on AWS",
        "fix_state": "Fix deferred",
        "package_name": "rosa",
        "cpe": "cpe:/a:redhat:openshift_service_on_aws:1"
      },
      {
        "product_name": "Red Hat Openshift Sandboxed Containers",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-monitor-rhel9",
        "cpe": "cpe:/a:redhat:openshift_sandboxed_containers:1"
      },
      {
        "product_name": "Red Hat OpenShift Update Service",
        "fix_state": "Fix deferred",
        "package_name": "openshift-update-service/cincinnati-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_update_service:5"
      },
      {
        "product_name": "Red Hat OpenShift Update Service",
        "fix_state": "Fix deferred",
        "package_name": "openshift-update-service/openshift-update-service-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_update_service:5"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Fix deferred",
        "package_name": "kubevirt",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "etcd",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "golang-github-infrawatch-apputils",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/osp-director-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "etcd",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "golang-github-infrawatch-apputils",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/osp-director-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "golang-github-openstack-k8s-operators-os-diff",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso-operators/sg-core-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "stf/sg-core-rhel8",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/clair-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite:el8/yggdrasil-worker-forwarder",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "yggdrasil-worker-forwarder",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Service Interconnect 2",
        "fix_state": "Fix deferred",
        "package_name": "skupper-cli",
        "cpe": "cpe:/a:redhat:service_interconnect:2"
      },
      {
        "product_name": "Red Hat Web Terminal",
        "fix_state": "Fix deferred",
        "package_name": "web-terminal-tech-preview/web-terminal-exec-rhel8",
        "cpe": "cpe:/a:redhat:webterminal:1"
      },
      {
        "product_name": "Red Hat Web Terminal",
        "fix_state": "Fix deferred",
        "package_name": "web-terminal/web-terminal-exec-rhel8",
        "cpe": "cpe:/a:redhat:webterminal:1"
      },
      {
        "product_name": "Red Hat Web Terminal",
        "fix_state": "Fix deferred",
        "package_name": "web-terminal/web-terminal-exec-rhel9",
        "cpe": "cpe:/a:redhat:webterminal:1"
      },
      {
        "product_name": "Self Node Remediation Operator",
        "fix_state": "Fix deferred",
        "package_name": "workload-availability/self-node-remediation-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_snr:0"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Fix deferred",
        "package_name": "rhoso-operators/sg-core-rhel9",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Fix deferred",
        "package_name": "stf/sg-core-rhel8",
        "cpe": "cpe:/a:redhat:stf:1.5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-4673\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-4673\nhttps://go.dev/cl/679257\nhttps://go.dev/issue/73816\nhttps://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A\nhttps://pkg.go.dev/vuln/GO-2025-3751"
    ],
    "name": "CVE-2025-4673",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-05-17T15:46:11Z",
    "bugzilla": {
      "description": "setuptools: Path Traversal Vulnerability in setuptools PackageIndex",
      "id": "2366982",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2366982"
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-22",
    "details": [
      "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.",
      "A path traversal vulnerability in the Python setuptools library allows attackers with limited system access to write files outside the intended temporary directory by manipulating package download URLs. This flaw bypasses basic filename sanitization and can lead to unauthorized overwrites of important system files, creating opportunities for further compromise. While it doesn't expose data or require user interaction, it poses a high integrity risk and is especially concerning in environments that rely on automated package handling or internal tooling built on setuptools."
    ],
    "statement": "Red Hat Product Security has rated this vulnerability \"Moderate\" based on the impact of the damage caused by a successful exploitation and the pre-requisites.\n* Exploitation requires that the attacker have limited code execution access to a Python environment where they can trigger the vulnerable PackageIndex.download() function—this might be via a script, plugin, or automated job. Full admin rights aren't needed but a user with no access at all will be unable to exploit this vulnerability.\n* The vulnerability impacts the integrity of the system within the same security boundary—it does not enable access or compromise across trust boundaries (e.g., from one container to another or from user space to kernel).\n* Successful exploitation only allows the attacker to \"create\" new files. The vulnerability does not provide access to existing files and by an extension to any confidential information. \n* Arbitrary file writes can overwrite critical config files, executables, or scripts. This can lead to persistent code execution, system misconfiguration, or unauthorized behavior, especially in automated environments. While overwriting critical files could theoretically lead to service disruption, the vulnerability in isolation does not inherently cause denial of service. The exploit doesn't target availability directly, and in many cases, systems may continue running.",
    "affected_release": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2025-08-26T00:00:00Z",
        "advisory": "RHSA-2025:14686",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "automation-controller-0:4.6.19-1.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2025-08-26T00:00:00Z",
        "advisory": "RHSA-2025:14686",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "automation-controller-0:4.6.19-1.el9ap"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-07-01T00:00:00Z",
        "advisory": "RHSA-2025:9940",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "python-setuptools-0:69.0.3-12.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2025-07-23T00:00:00Z",
        "advisory": "RHSA-2025:11607",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "python3-setuptools-0:39.2.0-10.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:11984",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "python-setuptools-0:0.9.8-7.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-15T00:00:00Z",
        "advisory": "RHSA-2025:11043",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.11-setuptools-0:65.5.1-4.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-15T00:00:00Z",
        "advisory": "RHSA-2025:11044",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.12-setuptools-0:68.2.2-5.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-08-28T00:00:00Z",
        "advisory": "RHSA-2025:14900",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python39:3.9-8100020250823160619.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-08-28T00:00:00Z",
        "advisory": "RHSA-2025:14900",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python39-devel:3.9-8100020250823160619.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-08-28T00:00:00Z",
        "advisory": "RHSA-2025:14900",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "python39:3.9-8100020250823160619.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-08-28T00:00:00Z",
        "advisory": "RHSA-2025:14900",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "python39-devel:3.9-8100020250823160619.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-15T00:00:00Z",
        "advisory": "RHSA-2025:11036",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "python-setuptools-0:39.2.0-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11426",
        "cpe": "cpe:/o:redhat:rhel_aus:8.2",
        "package": "python-setuptools-0:39.2.0-5.el8_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-09-08T00:00:00Z",
        "advisory": "RHSA-2025:15411",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "python39:3.9-8040020250825101027.63cd9eba"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11425",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "python-setuptools-0:39.2.0-6.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2025-09-08T00:00:00Z",
        "advisory": "RHSA-2025:15411",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "python39:3.9-8040020250825101027.63cd9eba"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11425",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "python-setuptools-0:39.2.0-6.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-09-08T00:00:00Z",
        "advisory": "RHSA-2025:15410",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "python39:3.9-8060020250826083212.6a631399"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11424",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "python-setuptools-0:39.2.0-7.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-09-08T00:00:00Z",
        "advisory": "RHSA-2025:15410",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "python39:3.9-8060020250826083212.6a631399"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11424",
        "cpe": "cpe:/o:redhat:rhel_tus:8.6",
        "package": "python-setuptools-0:39.2.0-7.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-09-08T00:00:00Z",
        "advisory": "RHSA-2025:15410",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "python39:3.9-8060020250826083212.6a631399"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11424",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.6",
        "package": "python-setuptools-0:39.2.0-7.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2025-08-13T00:00:00Z",
        "advisory": "RHSA-2025:13804",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "python3.11-setuptools-0:65.5.1-2.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11427",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "python-setuptools-0:39.2.0-7.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2025-08-13T00:00:00Z",
        "advisory": "RHSA-2025:13804",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "python3.11-setuptools-0:65.5.1-2.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2025-09-08T00:00:00Z",
        "advisory": "RHSA-2025:15408",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "python39:3.9-8080020250901141228.93c2fc2f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11427",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "python-setuptools-0:39.2.0-7.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11463",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "fence-agents-0:4.10.0-86.el9_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-08-05T00:00:00Z",
        "advisory": "RHSA-2025:12834",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.12-setuptools-0:68.2.2-5.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-08-11T00:00:00Z",
        "advisory": "RHSA-2025:13578",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.11-setuptools-0:65.5.1-4.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-07T00:00:00Z",
        "advisory": "RHSA-2025:10407",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "python-setuptools-0:53.0.0-13.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11464",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "fence-agents-0:4.10.0-20.el9_0.23"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-07-23T00:00:00Z",
        "advisory": "RHSA-2025:11584",
        "cpe": "cpe:/o:redhat:rhel_e4s:9.0",
        "package": "python-setuptools-0:53.0.0-13.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2025-07-15T00:00:00Z",
        "advisory": "RHSA-2025:11101",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "fence-agents-0:4.10.0-43.el9_2.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2025-08-13T00:00:00Z",
        "advisory": "RHSA-2025:13803",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "python3.11-setuptools-0:65.5.1-2.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2025-07-29T00:00:00Z",
        "advisory": "RHSA-2025:12020",
        "cpe": "cpe:/o:redhat:rhel_e4s:9.2",
        "package": "python-setuptools-0:53.0.0-12.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-07-15T00:00:00Z",
        "advisory": "RHSA-2025:11102",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "fence-agents-0:4.10.0-62.el9_4.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-08-12T00:00:00Z",
        "advisory": "RHSA-2025:13668",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.12-setuptools-0:68.2.2-3.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-08-12T00:00:00Z",
        "advisory": "RHSA-2025:13669",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.11-setuptools-0:65.5.1-2.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:11868",
        "cpe": "cpe:/o:redhat:rhel_eus:9.4",
        "package": "python-setuptools-0:53.0.0-12.el9_4.2"
      },
      {
        "product_name": "Builds for Red Hat OpenShift 1.4.1",
        "release_date": "2025-07-10T00:00:00Z",
        "advisory": "RHSA-2025:10787",
        "cpe": "cpe:/a:redhat:openshift_builds:1.4::el9",
        "package": "openshift-builds/openshift-builds-shared-resource-rhel9:1.4.1-1751884063"
      },
      {
        "product_name": "Builds for Red Hat OpenShift 1.4.1",
        "release_date": "2025-07-10T00:00:00Z",
        "advisory": "RHSA-2025:10787",
        "cpe": "cpe:/a:redhat:openshift_builds:1.4::el9",
        "package": "openshift-builds/openshift-builds-shared-resource-webhook-rhel9:1.4.1-1751884061"
      },
      {
        "product_name": "Builds for Red Hat OpenShift 1.4.1",
        "release_date": "2025-07-15T00:00:00Z",
        "advisory": "RHSA-2025:11146",
        "cpe": "cpe:/a:redhat:openshift_builds:1.4::el9",
        "package": "openshift-builds/openshift-builds-shared-resource-rhel9:1.4.1-1752476536"
      },
      {
        "product_name": "Builds for Red Hat OpenShift 1.4.1",
        "release_date": "2025-07-15T00:00:00Z",
        "advisory": "RHSA-2025:11146",
        "cpe": "cpe:/a:redhat:openshift_builds:1.4::el9",
        "package": "openshift-builds/openshift-builds-shared-resource-webhook-rhel9:1.4.1-1752476548"
      },
      {
        "product_name": "Builds for Red Hat OpenShift 1.5.2",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11388",
        "cpe": "cpe:/a:redhat:openshift_builds:1.5::el9",
        "package": "openshift-builds/openshift-builds-shared-resource-rhel9:1.5.0-1752236355"
      },
      {
        "product_name": "Builds for Red Hat OpenShift 1.5.2",
        "release_date": "2025-07-17T00:00:00Z",
        "advisory": "RHSA-2025:11388",
        "cpe": "cpe:/a:redhat:openshift_builds:1.5::el9",
        "package": "openshift-builds/openshift-builds-shared-resource-webhook-rhel9:1.5.0-1752236353"
      },
      {
        "product_name": "Red Hat Developer Hub 1.5",
        "release_date": "2025-07-14T00:00:00Z",
        "advisory": "RHSA-2025:10992",
        "cpe": "cpe:/a:redhat:rhdh:1.5::el9",
        "package": "rhdh/rhdh-hub-rhel9:1.5.3-1752159545"
      },
      {
        "product_name": "Red Hat Developer Hub 1.6",
        "release_date": "2025-06-30T00:00:00Z",
        "advisory": "RHSA-2025:9966",
        "cpe": "cpe:/a:redhat:rhdh:1.6::el9",
        "package": "rhdh/rhdh-hub-rhel9:1.6.2-1750887220"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 1.5",
        "release_date": "2025-11-03T00:00:00Z",
        "advisory": "RHSA-2025:19421",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1.5::el9",
        "package": "rhelai1/instructlab-intel-rhel9:1.5.4-1761050413"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 1.5",
        "release_date": "2025-11-03T00:00:00Z",
        "advisory": "RHSA-2025:19422",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1.5::el9",
        "package": "rhelai1/bootc-intel-rhel9:1.5.4-1761060689"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 1.5",
        "release_date": "2025-11-03T00:00:00Z",
        "advisory": "RHSA-2025:19423",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1.5::el9",
        "package": "rhelai1/instructlab-nvidia-rhel9:1.5.4-1761220254"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 1.5",
        "release_date": "2025-11-03T00:00:00Z",
        "advisory": "RHSA-2025:19424",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1.5::el9",
        "package": "rhelai1/bootc-azure-amd-rhel9:1.5.4-1761073793"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 1.5",
        "release_date": "2025-11-03T00:00:00Z",
        "advisory": "RHSA-2025:19425",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1.5::el9",
        "package": "rhelai1/instructlab-amd-rhel9:1.5.4-1761043227"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 1.5",
        "release_date": "2025-11-03T00:00:00Z",
        "advisory": "RHSA-2025:19426",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1.5::el9",
        "package": "rhelai1/bootc-gcp-nvidia-rhel9:1.5.4-1761236079"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 1.5",
        "release_date": "2025-11-03T00:00:00Z",
        "advisory": "RHSA-2025:19427",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1.5::el9",
        "package": "rhelai1/bootc-amd-rhel9:1.5.4-1761064179"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 1.5",
        "release_date": "2025-11-03T00:00:00Z",
        "advisory": "RHSA-2025:19428",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1.5::el9",
        "package": "rhelai1/bootc-nvidia-rhel9:1.5.4-1761228838"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 1.5",
        "release_date": "2025-11-03T00:00:00Z",
        "advisory": "RHSA-2025:19429",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1.5::el9",
        "package": "rhelai1/bootc-aws-nvidia-rhel9:1.5.4-1761236150"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 1.5",
        "release_date": "2025-11-03T00:00:00Z",
        "advisory": "RHSA-2025:19430",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1.5::el9",
        "package": "rhelai1/bootc-azure-nvidia-rhel9:1.5.4-1761238736"
      },
      {
        "product_name": "Red Hat Quay 3.14",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4215",
        "cpe": "cpe:/a:redhat:quay:3.14::el8",
        "package": "quay/quay-rhel8:1773097621"
      },
      {
        "product_name": "Red Hat Satellite 6.17",
        "release_date": "2025-07-10T00:00:00Z",
        "advisory": "RHSA-2025:10809",
        "cpe": "cpe:/a:redhat:satellite:6.17::el9",
        "package": "satellite/iop-advisor-engine-rhel9:6.17"
      }
    ],
    "package_state": [
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/cert-manager-istio-csr-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/cert-manager-operator-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/jetstack-cert-manager-acmesolver-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/jetstack-cert-manager-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Custom Metric Autoscaler operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "custom-metrics-autoscaler/custom-metrics-autoscaler-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/elasticsearch6-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/logging-curator5-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Not affected",
        "package_name": "network-observability/network-observability-cli-rhel9",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Not affected",
        "package_name": "network-observability/network-observability-operator-bundle",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Not affected",
        "package_name": "network-observability/network-observability-rhel9-operator",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-console-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-chains-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-cli-tkn-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-console-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-console-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-entrypoint-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-events-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-git-init-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-hub-api-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-hub-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-hub-db-migration-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-hub-db-migration-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-hub-ui-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-hub-ui-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-nop-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-operator-proxy-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-operator-webhook-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-pipelines-as-code-cli-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-pipelines-as-code-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-pipelines-as-code-webhook-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-resolvers-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-results-api-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-results-watcher-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-sidecarlogresults-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-triggers-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-triggers-core-interceptors-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-triggers-eventlistenersink-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-triggers-webhook-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-webhook-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines/pipelines-workingdirinit-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Not affected",
        "package_name": "openshift-serverless-1/kn-ekb-dispatcher-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Not affected",
        "package_name": "openshift-serverless-1/kn-ekb-kafka-controller-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Not affected",
        "package_name": "openshift-serverless-1/kn-ekb-post-install-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Not affected",
        "package_name": "openshift-serverless-1/kn-ekb-receiver-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Not affected",
        "package_name": "openshift-serverless-1/kn-ekb-webhook-kafka-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "Red Hat build of Quarkus Native builder",
        "fix_state": "Affected",
        "package_name": "mandrel-for-jdk-21-rhel8",
        "cpe": "cpe:/a:redhat:quarkus:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "python-setuptools",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "python3x-setuptools",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Will not fix",
        "package_name": "rhelai1/docling-serve-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Will not fix",
        "package_name": "rhelai1/ui-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Offline Knowledge Portal",
        "fix_state": "Affected",
        "package_name": "offline-knowledge-portal/rhokp-rhel9",
        "cpe": "cpe:/a:redhat:offline_knowledge_portal:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-dashboard-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-feast-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-feature-server-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-api-server-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-artifact-manager-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-cache-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-modelmesh-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-trustyai-service-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhods/odh-ml-pipelines-api-server-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhods/odh-ml-pipelines-artifact-manager-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhods/odh-ml-pipelines-cache-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhods/odh-ml-pipelines-persistenceagent-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhods/odh-ml-pipelines-scheduledworkflow-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/microshift-bootc-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ansible-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ztp-site-generate-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "python-setuptools",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/udi-rhel8",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/udi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/client-server-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/rekor-backfill-redis-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/rekor-cli-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/rekor-search-ui-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/rekor-server-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/segment-reporting-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/trillian-database-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/trillian-redis-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/tuffer-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/tuftool-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Not affected",
        "package_name": "stf/prometheus-webhook-snmp-rhel8",
        "cpe": "cpe:/a:redhat:stf:1.5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-47273\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-47273\nhttps://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88\nhttps://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b\nhttps://github.com/pypa/setuptools/issues/4946\nhttps://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf"
    ],
    "name": "CVE-2025-47273",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-07-07T15:25:47Z",
    "bugzilla": {
      "description": "redis: Redis Unauthenticated Denial of Service",
      "id": "2376857",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376857"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.",
      "A flaw was found in Redis. Unauthenticated connections can trigger repeated IP protocol errors, leading to client starvation and an application-level denial of service. This flaw allows an attacker to induce this condition without authentication. This issue results in a denial of service condition for connected clients. The root cause is related to the improper handling of network traffic."
    ],
    "statement": "The severity of this vulnerability is rated Moderate as it does not impact system availability. The effects are confined to the application layer without compromising the underlying system stability.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11401",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "valkey-0:8.0.4-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:12006",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "redis:6-8100020250716063446.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12789",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "redis:6-8040020250801055559.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12789",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "redis:6-8040020250801055559.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12769",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "redis:6-8060020250731141235.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12769",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "redis:6-8060020250731141235.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12769",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "redis:6-8060020250731141235.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12768",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "redis:6-8080020250730132007.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12768",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "redis:6-8080020250730132007.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-21T00:00:00Z",
        "advisory": "RHSA-2025:11453",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "redis-0:6.2.19-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:12008",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "redis:7-9060020250716081121.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-07-31T00:00:00Z",
        "advisory": "RHSA-2025:12468",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "redis-0:6.2.6-1.el9_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2025-08-01T00:00:00Z",
        "advisory": "RHSA-2025:12478",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "redis-0:6.2.7-1.el9_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12524",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "redis-0:6.2.7-1.el9_4.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-08-05T00:00:00Z",
        "advisory": "RHSA-2025:12892",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "redis:7-9040020250730125543.9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/aap-cloud-metrics-collector-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/ansible-dev-tools-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Not affected",
        "package_name": "rhdh/rhdh-hub-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Not affected",
        "package_name": "rhdh/rhdh-rhel9-operator",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Discovery 1",
        "fix_state": "Not affected",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "valkey",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-aws-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-gcp-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-intel-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/gemma-2-9b-it",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/gemma-2-9b-it-fp8",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/granite-3.1-8b-lab-v2.1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/granite-3.1-8b-starter-v2.1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/instructlab-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/instructlab-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-gemma-2-9b-it",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-gemma-2-9b-it-fp8",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-granite-3-1-8b-lab-v2-1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/modelcar-granite-3-1-8b-starter-v2-1",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-argoexec-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-feast-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-launcher-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-48367\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-48367\nhttps://github.com/redis/redis/commit/bde62951accfc4bb0a516276fd0b4b307e140ce2\nhttps://github.com/redis/redis/releases/tag/6.2.19\nhttps://github.com/redis/redis/releases/tag/7.2.10\nhttps://github.com/redis/redis/releases/tag/7.4.5\nhttps://github.com/redis/redis/releases/tag/8.0.3\nhttps://github.com/redis/redis/security/advisories/GHSA-4q32-c38c-pwgq\nhttps://github.com/valkey-io/valkey/releases"
    ],
    "name": "CVE-2025-48367",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-05-23T00:00:00Z",
    "bugzilla": {
      "description": "Ghostscript: Ghostscript Argument Sanitization Vulnerability",
      "id": "2368134",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368134"
    },
    "cvss3": {
      "cvss3_base_score": "2.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-212",
    "details": [
      "gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.",
      "A flaw was found in Artifex Ghostscript. This vulnerability may allow arbitrary code execution via a crafted PostScript document."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "ghostscript",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "ghostscript",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ghostscript",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "ghostscript",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ghostscript",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-48708\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-48708\nhttps://bugs.ghostscript.com/show_bug.cgi?id=708446\nhttps://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=b587663c623b4462f9e78686a31fd880207303ee"
    ],
    "name": "CVE-2025-48708",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-06-02T00:00:00Z",
    "bugzilla": {
      "description": "valkey: Valkey Integer Underflow Vulnerability",
      "id": "2369697",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369697"
    },
    "cvss3": {
      "cvss3_base_score": "3.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-191",
    "details": [
      "setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.",
      "A flaw was found in valkey. An integer underflow in the `setDeferredReply` function of `networking.c` allows an adjacent network attacker to potentially trigger unexpected behavior. This underflow occurs when calculating `prev->size - prev->used`, leading to a condition that may result in a denial of service. The vulnerability is triggered by processing a specially crafted network packet."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "valkey",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-49112\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-49112\nhttps://github.com/redis/redis/blob/994bc96bb1744cb153392fc96bdba43eae56e17f/src/networking.c#L783\nhttps://github.com/valkey-io/valkey/blob/daea05b1e26db29bfd1c033e27f9d519a2f8ccbb/src/networking.c#L886\nhttps://github.com/valkey-io/valkey/pull/2101"
    ],
    "name": "CVE-2025-49112",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-08-06T14:33:12Z",
    "bugzilla": {
      "description": "apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation",
      "id": "2512077",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2512077"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-208",
    "details": [
      "APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android.\nUsers are recommended to upgrade to version 1.6.4, which fixes this issue.",
      "A flaw was found in Apache Portable Runtime Utility (apr-util). The `apr_password_validate()` function does not perform constant-time comparisons for hashes or passwords. This vulnerability allows a remote attacker to conduct a timing attack, particularly on platforms without `crypt()` such as Windows, BeOS, NetWare, or Android. By observing the time differences in comparisons, an attacker could potentially deduce the content of sensitive information like password hashes."
    ],
    "statement": "This vulnerability is assessed as Low Impact due to significant practical exploitation barriers. While the theoretical outcome of a successful timing attack is hash disclosure (Confidentiality: High), isolating microsecond-level comparison differences over a network is rendered practically infeasible by unpredictable network latency, packet jitter, and server scheduling noise (Attack Complexity: High). Additionally, RHEL environments natively rely on the system crypt() implementation for standard password checks, bypassing the vulnerable non-constant-time fallback code path in standard deployment scenarios.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-22T00:00:00Z",
        "advisory": "RHSA-2026:58474",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "apr-util-main-1.6.5-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-49506\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-49506\nhttps://lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5"
    ],
    "name": "CVE-2025-49506",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-10-23T00:00:00Z",
    "bugzilla": {
      "description": "audiofile: NULL pointer dereference in the ModuleState::setup function",
      "id": "2406048",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2406048"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.",
      "A flaw was found in the Audiofile library. Processing a specially crafted input file can trigger a NULL pointer dereference, causing a crash to the application linked to the library and resulting in a denial of service."
    ],
    "statement": "To exploit this issue, an attacker needs to be able to process a specially crafted input file with the application linked to the Audiofile library. Additionally, the only security impact of this vulnerability is a denial of service. Due to these reasons, this flaw has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23457",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "audiofile-1:0.3.6-10.el7_9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "audiofile",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-50950\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-50950\nhttps://github.com/mpruett/audiofile/issues/66"
    ],
    "name": "CVE-2025-50950",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-05-26T18:31:06Z",
    "bugzilla": {
      "description": "assimp: Assimp: Out-of-bounds Read Vulnerability",
      "id": "2368631",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368631"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDLImporter::InternReadFile_Quake1 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation leads to out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.",
      "A flaw was found in the Open Asset Import Library (Assimp). This vulnerability allows an out-of-bounds read via manipulation of an MDL file."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "qt5-qt3d",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-5200\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-5200\nhttps://github.com/assimp/assimp/issues/6128\nhttps://github.com/assimp/assimp/issues/6172\nhttps://github.com/user-attachments/files/20208985/line-452-reproducer.zip\nhttps://vuldb.com/?ctiid.310289\nhttps://vuldb.com/?id.310289\nhttps://vuldb.com/?submit.578005"
    ],
    "name": "CVE-2025-5200",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-05-26T19:00:09Z",
    "bugzilla": {
      "description": "assimp: Open Asset Import Library Assimp LWOLoader.cpp CountVertsAndFacesLWO2 out-of-bounds",
      "id": "2369039",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369039"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function LWOImporter::CountVertsAndFacesLWO2 of the file assimp/code/AssetLib/LWO/LWOLoader.cpp. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.",
      "A fuzzer test discovered a heap based buffer overflow in the Open Asset Import Library Assimp on version 5.4.3. The LWOImporter::CountVertsAndFacesLWO2 function in the assimp/code/AssetLib/LWO/LWOLoader.cpp file is affected. The manipulation leads to out-of-bounds read, which can lead to an application crash. The attacker needs to be local in order to exploit this vulnerability."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "qt5-qt3d",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-5201\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-5201\nhttps://github.com/assimp/assimp/issues/6128\nhttps://github.com/assimp/assimp/issues/6173\nhttps://github.com/assimp/assimp/issues/6174\nhttps://github.com/user-attachments/files/20209125/line-832-reproducer.zip\nhttps://vuldb.com/?ctiid.310290\nhttps://vuldb.com/?id.310290\nhttps://vuldb.com/?submit.578006"
    ],
    "name": "CVE-2025-5201",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-05-26T20:00:09Z",
    "bugzilla": {
      "description": "assimp: Assimp Out-of-Bounds Read Vulnerability",
      "id": "2368649",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368649"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this issue is the function SkipSpaces in the library assimp/include/assimp/ParsingUtils.h. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.",
      "A flaw was found in the Open Asset Import Library (Assimp). This vulnerability allows an out-of-bounds read via local access."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "qt5-qt3d",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-5203\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-5203\nhttps://github.com/assimp/assimp/issues/6128\nhttps://github.com/assimp/assimp/issues/6175\nhttps://github.com/user-attachments/files/20209469/reproducer.zip\nhttps://vuldb.com/?ctiid.310292\nhttps://vuldb.com/?id.310292\nhttps://vuldb.com/?submit.578012"
    ],
    "name": "CVE-2025-5203",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-05-26T20:31:06Z",
    "bugzilla": {
      "description": "assimp: Assimp Out-of-Bounds Read Vulnerability",
      "id": "2368650",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368650"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::ParseSkinLump_3DGS_MDL7 of the file assimp/code/AssetLib/MDL/MDLMaterialLoader.cpp. The manipulation leads to out-of-bounds read. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.",
      "A flaw was found in assimp. The flawed bounds check in the MDLImporter::ParseSkinLump_3DGS_MDL7 function leads to an out-of-bounds read. A local attacker is required to trigger the vulnerability by manipulating input during file parsing. This results in a denial of service. Low privileges are needed to exploit the issue."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "qt5-qt3d",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-5204\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-5204\nhttps://github.com/assimp/assimp/issues/6128\nhttps://github.com/assimp/assimp/issues/6176\nhttps://github.com/user-attachments/files/20209911/ParseSkinLump-reproducer.zip\nhttps://vuldb.com/?ctiid.310293\nhttps://vuldb.com/?id.310293\nhttps://vuldb.com/?submit.578013"
    ],
    "name": "CVE-2025-5204",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-10-21T20:02:54Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Oct 2025)",
      "id": "2405534",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405534"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23008",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.7-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23134",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020251125095949.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23137",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020251124123230.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23109",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.44-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23111",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020251124122854.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-53040\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-53040\nhttps://www.oracle.com/security-alerts/cpuoct2025.html#AppendixMSQL"
    ],
    "name": "CVE-2025-53040",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-10-21T20:02:55Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Oct 2025)",
      "id": "2405544",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405544"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23008",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.7-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23134",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020251125095949.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23137",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020251124123230.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23109",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.44-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23111",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020251124122854.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-53042\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-53042\nhttps://www.oracle.com/security-alerts/cpuoct2025.html#AppendixMSQL"
    ],
    "name": "CVE-2025-53042",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-10-21T20:02:56Z",
    "bugzilla": {
      "description": "mysql: InnoDB unspecified vulnerability (CPU Oct 2025)",
      "id": "2405491",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405491"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23008",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.7-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23134",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020251125095949.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23137",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020251124123230.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23109",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.44-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23111",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020251124122854.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-53044\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-53044\nhttps://www.oracle.com/security-alerts/cpuoct2025.html#AppendixMSQL"
    ],
    "name": "CVE-2025-53044",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-10-21T20:02:56Z",
    "bugzilla": {
      "description": "mysql: InnoDB unspecified vulnerability (CPU Oct 2025)",
      "id": "2405523",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405523"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23008",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.7-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23134",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020251125095949.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23137",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020251124123230.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23109",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.44-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23111",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020251124122854.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-53045\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-53045\nhttps://www.oracle.com/security-alerts/cpuoct2025.html#AppendixMSQL"
    ],
    "name": "CVE-2025-53045",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-10-21T20:02:59Z",
    "bugzilla": {
      "description": "mysql: DML unspecified vulnerability (CPU Oct 2025)",
      "id": "2405486",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405486"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23008",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.7-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23134",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020251125095949.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23137",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020251124123230.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23109",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.44-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23111",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020251124122854.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-53053\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-53053\nhttps://www.oracle.com/security-alerts/cpuoct2025.html#AppendixMSQL"
    ],
    "name": "CVE-2025-53053",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-10-21T20:02:59Z",
    "bugzilla": {
      "description": "mysql: InnoDB unspecified vulnerability (CPU Oct 2025)",
      "id": "2405514",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405514"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23008",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.7-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23134",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020251125095949.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23137",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020251124123230.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23109",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.44-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23111",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020251124122854.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-53054\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-53054\nhttps://www.oracle.com/security-alerts/cpuoct2025.html#AppendixMSQL"
    ],
    "name": "CVE-2025-53054",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-10-21T20:03:03Z",
    "bugzilla": {
      "description": "mysql: InnoDB unspecified vulnerability (CPU Oct 2025)",
      "id": "2405511",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405511"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23008",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.7-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23134",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020251125095949.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23137",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020251124123230.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23109",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.44-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23111",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020251124122854.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-53062\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-53062\nhttps://www.oracle.com/security-alerts/cpuoct2025.html#AppendixMSQL"
    ],
    "name": "CVE-2025-53062",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-10-21T20:03:06Z",
    "bugzilla": {
      "description": "mysql: Components Services unspecified vulnerability (CPU Oct 2025)",
      "id": "2405541",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405541"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23008",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.7-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23134",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020251125095949.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23137",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020251124123230.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23109",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.44-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23111",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020251124122854.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-53069\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-53069\nhttps://www.oracle.com/security-alerts/cpuoct2025.html#AppendixMSQL"
    ],
    "name": "CVE-2025-53069",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-06-04T10:30:46Z",
    "bugzilla": {
      "description": "wireshark: Buffer Overflow in Wireshark",
      "id": "2370225",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370225"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-120",
    "details": [
      "Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file",
      "A buffer overflow vulnerability was found in Wireshark. This vulnerability is triggered when a user views a specifically malformed packet or a pcap file with such a malformed packet."
    ],
    "statement": "The report makes the assumption that the active user is the root user and calculates the impact based on that assumption. It is not advised to conduct normal operations as the root user and when running as a non-root user, the impact is limited.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-5601\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-5601\nhttps://gitlab.com/wireshark/wireshark/-/commit/53213086304caa3dfbdd7dc39c2668a3aea1a5c0\nhttps://gitlab.com/wireshark/wireshark/-/issues/20509\nhttps://www.wireshark.org/security/wnpa-sec-2025-02.html"
    ],
    "name": "CVE-2025-5601",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-10-29T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPDK - lib/nvmf."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-57275\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-57275"
    ],
    "name": "CVE-2025-57275",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-25T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A bug in POST request handling causes a crash under a certain condition.\n\nThis issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.\n\nUsers are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.\n\nA workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the default value is 0)."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-58136\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-58136"
    ],
    "name": "CVE-2025-58136",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-10-29T22:10:14Z",
    "bugzilla": {
      "description": "golang: archive/tar: Unbounded allocation when parsing GNU sparse map",
      "id": "2407258",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2407258"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.",
      "A flaw was found in the archive/tar package in the Go standard library. tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A specially crafted tar archive with a pax header indicating a big number of sparse regions can cause a Go program to try to allocate a large amount of memory, causing an out-of-memory condition and resulting in a denial of service."
    ],
    "statement": "To exploit this issue, an attacker needs to be able to process a specially crafted GNU tar pax 1.0 archive with the application using the archive/tar package. Additionally, this issue can cause the Go application to allocate a large amount of memory, eventually leading to an out-of-memory condition and resulting in a denial of service with no other security impact. Due to these reasons, this flaw has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Ceph Storage 8.1",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2711",
        "cpe": "cpe:/a:redhat:ceph_storage:8.1::el9",
        "package": "ceph-2:19.2.1-331.el9cp"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21816",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "delve-0:1.25.2-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21816",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "golang-0:1.25.3-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-11-25T00:00:00Z",
        "advisory": "RHSA-2025:22012",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "buildah-2:1.41.6-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23088",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "grafana-0:10.2.6-21.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23294",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "skopeo-2:1.20.0-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23295",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "podman-7:5.6.0-8.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1837",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "osbuild-composer-0:149-4.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1838",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "image-builder-0:31-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21779",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "delve-0:1.25.2-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21779",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "golang-0:1.25.3-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23001",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "grafana-0:10.2.6-19.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23347",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "podman-6:5.4.0-14.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23348",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "skopeo-2:1.18.1-3.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-01-27T00:00:00Z",
        "advisory": "RHSA-2026:1378",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "osbuild-composer-0:134.1-4.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-03T00:00:00Z",
        "advisory": "RHSA-2025:22668",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "go-toolset:rhel8-8100020251201162956.a3795dee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23374",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "container-tools:rhel8-8100020251204131058.afee755d"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23948",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "grafana-0:9.2.10-26.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-27T00:00:00Z",
        "advisory": "RHSA-2026:1380",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "osbuild-composer-0:101.4-2.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23740",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "go-toolset:rhel8-8020020251212160632.02f7cb7a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-01-07T00:00:00Z",
        "advisory": "RHSA-2026:0244",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "grafana-0:6.3.6-9.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23741",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "go-toolset:rhel8-8040020251212161217.5081a262"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-01-07T00:00:00Z",
        "advisory": "RHSA-2026:0243",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "grafana-0:7.3.6-11.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0987",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "osbuild-composer-0:28.7-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23741",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "go-toolset:rhel8-8040020251212161217.5081a262"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-01-07T00:00:00Z",
        "advisory": "RHSA-2026:0243",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "grafana-0:7.3.6-11.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0987",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "osbuild-composer-0:28.7-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23733",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "go-toolset:rhel8-8060020251219132124.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-01-07T00:00:00Z",
        "advisory": "RHSA-2026:0246",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "grafana-0:7.5.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:1025",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "osbuild-composer-0:46.3-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10703",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "container-tools:rhel8-8060020260422144418.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23733",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "go-toolset:rhel8-8060020251219132124.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-01-07T00:00:00Z",
        "advisory": "RHSA-2026:0246",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "grafana-0:7.5.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:1025",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "osbuild-composer-0:46.3-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10703",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "container-tools:rhel8-8060020260422144418.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23733",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "go-toolset:rhel8-8060020251219132124.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-01-07T00:00:00Z",
        "advisory": "RHSA-2026:0246",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "grafana-0:7.5.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:1025",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "osbuild-composer-0:46.3-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10703",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "container-tools:rhel8-8060020260422144418.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23737",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "go-toolset:rhel8-8080020251215161342.17f3f959"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-01-07T00:00:00Z",
        "advisory": "RHSA-2026:0245",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "grafana-0:7.5.15-8.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0973",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "osbuild-composer-0:75-5.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4693",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "container-tools:rhel8-8080020260226135022.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6191",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "container-tools:rhel8-8080020260325222945.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23737",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "go-toolset:rhel8-8080020251215161342.17f3f959"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-01-07T00:00:00Z",
        "advisory": "RHSA-2026:0245",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "grafana-0:7.5.15-8.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0973",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "osbuild-composer-0:75-5.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4693",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "container-tools:rhel8-8080020260226135022.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6191",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "container-tools:rhel8-8080020260325222945.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21815",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "delve-0:1.25.2-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21815",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "golang-0:1.25.3-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-11-25T00:00:00Z",
        "advisory": "RHSA-2025:22011",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "buildah-2:1.41.6-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23087",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "grafana-0:10.2.6-17.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23325",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "podman-6:5.6.0-9.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23326",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "skopeo-2:1.20.0-2.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-27T00:00:00Z",
        "advisory": "RHSA-2026:1377",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "image-builder-0:31-2.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-27T00:00:00Z",
        "advisory": "RHSA-2026:1381",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "osbuild-composer-0:149-3.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-12-09T00:00:00Z",
        "advisory": "RHSA-2025:22899",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "golang-0:1.17.13-8.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23736",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "grafana-0:7.5.11-12.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-01-07T00:00:00Z",
        "advisory": "RHSA-2026:0227",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "osbuild-composer-0:46.3-5.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8325",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "buildah-1:1.26.9-1.el9_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8325",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "podman-2:4.2.0-6.el9_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8325",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "skopeo-2:1.8.0-4.1.el9_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2025-11-26T00:00:00Z",
        "advisory": "RHSA-2025:22181",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "golang-0:1.19.13-20.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23747",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "grafana-0:9.0.9-9.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0314",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "osbuild-composer-0:76.1-3.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4532",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "buildah-1:1.29.5-1.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4533",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "podman-2:4.4.1-22.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5234",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "skopeo-2:1.11.2-0.1.el9_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21856",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "golang-0:1.21.13-12.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23746",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "grafana-0:9.2.10-24.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-07T00:00:00Z",
        "advisory": "RHSA-2026:0226",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "osbuild-composer-0:101.3-3.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0424",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "podman-4:4.9.4-19.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0426",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "buildah-2:1.33.13-2.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0477",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "skopeo-2:1.14.5-2.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21778",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "delve-0:1.25.2-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21778",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "golang-0:1.25.3-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2025-11-24T00:00:00Z",
        "advisory": "RHSA-2025:21964",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "buildah-2:1.39.6-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2025-11-25T00:00:00Z",
        "advisory": "RHSA-2025:22030",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "podman-5:5.4.0-15.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23002",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "grafana-0:10.2.6-16.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23394",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "skopeo-2:1.18.1-3.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-01-27T00:00:00Z",
        "advisory": "RHSA-2026:1379",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "osbuild-composer-0:132.2-4.el9_6"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26527",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "skopeo-2:1.9.4-8.rhaos4.12.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26541",
        "cpe": "cpe:/a:redhat:openshift:4.13::el8",
        "package": "podman-3:4.4.1-19.rhaos4.13.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26541",
        "cpe": "cpe:/a:redhat:openshift:4.13::el8",
        "package": "skopeo-2:1.11.3-6.rhaos4.13.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5086",
        "cpe": "cpe:/a:redhat:openshift:4.14::el8",
        "package": "podman-3:4.4.1-24.rhaos4.14.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5086",
        "cpe": "cpe:/a:redhat:openshift:4.14::el8",
        "package": "skopeo-2:1.11.3-6.rhaos4.14.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4418",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "cri-o-0:1.28.11-13.rhaos4.15.gitf722b2f.el9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4418",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "podman-3:4.4.1-36.rhaos4.15.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4418",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "skopeo-2:1.11.3-7.rhaos4.15.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4464",
        "cpe": "cpe:/a:redhat:openshift:4.16::el8",
        "package": "skopeo-2:1.14.5-5.rhaos4.16.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17595",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "podman-5:5.2.2-18.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:5866",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "skopeo-2:1.16.1-5.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17446",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "podman-5:5.2.2-11.rhaos4.18.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2071",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "cri-o-0:1.31.13-6.rhaos4.18.git7ed6156.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3875",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "skopeo-2:1.16.1-3.rhaos4.18.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:5876",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "skopeo-2:1.18.1-5.rhaos4.19.el9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21701",
        "cpe": "cpe:/a:redhat:openshift:4.20::el8",
        "package": "openshift-0:4.20.0-202605141748.p2.g2a0461f.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2025-12-02T00:00:00Z",
        "advisory": "RHSA-2025:22255",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "cri-o-0:1.33.6-2.rhaos4.20.git6d65309.el9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2082",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "cri-o-0:1.34.5-2.rhaos4.21.gita8af6ea.el9"
      },
      {
        "product_name": "Builds for Red Hat OpenShift 1.5.2",
        "release_date": "2025-12-04T00:00:00Z",
        "advisory": "RHSA-2025:22738",
        "cpe": "cpe:/a:redhat:openshift_builds:1.5::el9",
        "package": "openshift-builds/openshift-builds-waiters-rhel9:1.5.2-1764669053"
      },
      {
        "product_name": "cert-manager operator for Red Hat OpenShift 1.17",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5645",
        "cpe": "cpe:/a:redhat:cert_manager:1.17::el9",
        "package": "cert-manager/jetstack-cert-manager-acmesolver-rhel9:1774342146"
      },
      {
        "product_name": "cert-manager operator for Red Hat OpenShift 1.17",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5645",
        "cpe": "cpe:/a:redhat:cert_manager:1.17::el9",
        "package": "cert-manager/jetstack-cert-manager-rhel9:1774341716"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-01-23T00:00:00Z",
        "advisory": "RHSA-2026:1067",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/assisted-installer-agent-rhel9:1767710870"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-01-25T00:00:00Z",
        "advisory": "RHSA-2026:1071",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/cluster-proxy-rhel9:1768984469"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-01-25T00:00:00Z",
        "advisory": "RHSA-2026:1071",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/managedcluster-import-controller-rhel9:1768984115"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-01-25T00:00:00Z",
        "advisory": "RHSA-2026:1071",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/managed-serviceaccount-rhel9:1768984335"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-01-25T00:00:00Z",
        "advisory": "RHSA-2026:1071",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/multicloud-manager-rhel9:1768984592"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-01-25T00:00:00Z",
        "advisory": "RHSA-2026:1071",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/work-rhel9:1769096257"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13542",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/backplane-rhel9-operator:1777402015"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46885",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/must-gather-rhel9:1784849867"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47388",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/must-gather-rhel9:1784849867"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.7",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5636",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.7::el9",
        "package": "multicluster-engine/backplane-rhel9-operator:1773091107"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.7",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5636",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.7::el9",
        "package": "multicluster-engine/cluster-proxy-rhel9:1773091011"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.7",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5636",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.7::el9",
        "package": "multicluster-engine/managed-serviceaccount-rhel9:1773091077"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.7",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5636",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.7::el9",
        "package": "multicluster-engine/multicloud-manager-rhel9:1773741020"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.7",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5636",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.7::el9",
        "package": "multicluster-engine/work-rhel9:1773970968"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0671",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/assisted-installer-agent-rhel9:1767786197"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0722",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/cluster-proxy-rhel9:1765866768"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0722",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/managedcluster-import-controller-rhel9:1765866268"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0722",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/managed-serviceaccount-rhel9:1765865954"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0722",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/multicloud-manager-rhel9:1765865949"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0722",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/work-rhel9:1765872400"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-06-28T00:00:00Z",
        "advisory": "RHSA-2026:30650",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/must-gather-rhel9:1782158798"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8218",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/backplane-rhel9-operator:1775518980"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.9",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2571",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.9::el9",
        "package": "multicluster-engine/cluster-proxy-rhel9:1769752462"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.9",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2571",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.9::el9",
        "package": "multicluster-engine/managed-serviceaccount-rhel9:1770680575"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.9",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2571",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.9::el9",
        "package": "multicluster-engine/multicloud-manager-rhel9:1769744081"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.9",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2571",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.9::el9",
        "package": "multicluster-engine/work-rhel9:1769693824"
      },
      {
        "product_name": "Network Observability (NETOBSERV) 1.11.1",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2900",
        "cpe": "cpe:/a:redhat:network_observ_optr:1.11::el9",
        "package": "network-observability/network-observability-rhel9-operator:1771230433"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2343",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-mustgather-rhel9:1768627772"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2343",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-rhel9-operator:1768640301"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2343",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-velero-plugin-rhel9:1768602558"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2343",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-velero-rhel9:1768624122"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5633",
        "cpe": "cpe:/a:redhat:acm:2.12::el9",
        "package": "rhacm2/acm-governance-policy-addon-controller-rhel9:1773233435"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5633",
        "cpe": "cpe:/a:redhat:acm:2.12::el9",
        "package": "rhacm2/acm-grafana-rhel9:1774002166"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5633",
        "cpe": "cpe:/a:redhat:acm:2.12::el9",
        "package": "rhacm2/acm-multicluster-observability-addon-rhel9:1773674653"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5633",
        "cpe": "cpe:/a:redhat:acm:2.12::el9",
        "package": "rhacm2/acm-volsync-addon-controller-rhel9:1773531422"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5633",
        "cpe": "cpe:/a:redhat:acm:2.12::el9",
        "package": "rhacm2/multiclusterhub-rhel9:1773145770"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5633",
        "cpe": "cpe:/a:redhat:acm:2.12::el9",
        "package": "rhacm2/prometheus-rhel9:1773680743"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5633",
        "cpe": "cpe:/a:redhat:acm:2.12::el9",
        "package": "rhacm2/thanos-rhel9:1773680856"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-01-14T00:00:00Z",
        "advisory": "RHSA-2026:0627",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/acm-governance-policy-addon-controller-rhel9:1768001933"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-01-14T00:00:00Z",
        "advisory": "RHSA-2026:0627",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/acm-multicluster-observability-addon-rhel9:1768246413"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-01-14T00:00:00Z",
        "advisory": "RHSA-2026:0627",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/prometheus-rhel9:1768284628"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-01-14T00:00:00Z",
        "advisory": "RHSA-2026:0627",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/thanos-rhel9:1768316963"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0718",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/acm-governance-policy-addon-controller-rhel9:1768001933"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0718",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/acm-grafana-rhel9:1767570373"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0718",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/acm-multicluster-observability-addon-rhel9:1768246413"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0718",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/acm-volsync-addon-controller-rhel9:1767570359"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0718",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/prometheus-rhel9:1768284628"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0718",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/thanos-rhel9:1768316963"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/multiclusterhub-rhel9:1774915533"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2351",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/volsync-rhel9:1770249158"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2572",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/prometheus-rhel9:1770050498"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2572",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/thanos-rhel9:1770050123"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0527",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/volsync-rhel9:1767718573"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-01-25T00:00:00Z",
        "advisory": "RHSA-2026:1072",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/acm-governance-policy-addon-controller-rhel9:1768002005"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-01-25T00:00:00Z",
        "advisory": "RHSA-2026:1072",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/acm-grafana-rhel9:1768261554"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-01-25T00:00:00Z",
        "advisory": "RHSA-2026:1072",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/acm-multicluster-observability-addon-rhel9:1768328729"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-01-25T00:00:00Z",
        "advisory": "RHSA-2026:1072",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/acm-volsync-addon-controller-rhel9:1768229100"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-01-25T00:00:00Z",
        "advisory": "RHSA-2026:1072",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/prometheus-rhel9:1768415988"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-01-25T00:00:00Z",
        "advisory": "RHSA-2026:1072",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/thanos-rhel9:1768109434"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13548",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/multiclusterhub-rhel9:1776693014"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1517",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1769615659"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1517",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-scanner-rhel8:1769125501"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2350",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-scanner-rhel8:1769492398"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2568",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-scanner-rhel8:1769577723"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2737",
        "cpe": "cpe:/a:redhat:ceph_storage:8::el9",
        "package": "rhceph/grafana-rhel9:1770630607"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7291",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-26-main-1.26.2-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7385",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-25-main-1.25.9-1.hum1"
      },
      {
        "product_name": "Red Hat Migration Toolkit 1.8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41928",
        "cpe": "cpe:/a:redhat:rhmt:1.8::el8",
        "package": "rhmtc/openshift-migration-controller-rhel8:1783953372"
      },
      {
        "product_name": "Red Hat Migration Toolkit 1.8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41928",
        "cpe": "cpe:/a:redhat:rhmt:1.8::el8",
        "package": "rhmtc/openshift-migration-registry-rhel8:1783914276"
      },
      {
        "product_name": "Red Hat Migration Toolkit for Applications 8.2",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56347",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8.2::el9",
        "package": "mta/mta-analyzer-addon-rhel9:1786482470"
      },
      {
        "product_name": "Red Hat Migration Toolkit for Applications 8.2",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56347",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8.2::el9",
        "package": "mta/mta-cli-rhel9:1786484104"
      },
      {
        "product_name": "Red Hat Migration Toolkit for Applications 8.2",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56347",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8.2::el9",
        "package": "mta/mta-discovery-addon-rhel9:1786481485"
      },
      {
        "product_name": "Red Hat Migration Toolkit for Applications 8.2",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56347",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8.2::el9",
        "package": "mta/mta-hub-rhel9:1786482352"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-01-29T00:00:00Z",
        "advisory": "RHSA-2026:1520",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1769006656"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-01-29T00:00:00Z",
        "advisory": "RHSA-2026:1520",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1769003292"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6226",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1774245790"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6226",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1773650060"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.22",
        "release_date": "2025-12-04T00:00:00Z",
        "advisory": "RHSA-2025:22759",
        "cpe": "cpe:/a:redhat:openshift_ai:2.22::el9",
        "package": "rhoai/odh-trustyai-service-rhel9:v2.22.3-1764596318"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.6.4",
        "release_date": "2025-12-04T00:00:00Z",
        "advisory": "RHSA-2025:22743",
        "cpe": "cpe:/a:redhat:openshift_builds:1.6::el9",
        "package": "openshift-builds/openshift-builds-waiters-rhel9:1.6.1-1764767096"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1773343512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/egress-router-cni-rhel8:1773340555"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1773344039"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/network-tools-rhel8:1773716649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1773344419"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1773343930"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1773345614"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1773345817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772165233"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1773343719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772164360"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1773335162"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1773334986"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1773335150"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1773335045"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1773340537"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1773335130"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1773335168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1773335245"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1773335131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1773335221"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1773335203"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1773335338"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1773335281"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1773335187"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1773335113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1773335078"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1773336201"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel8:1773335237"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1773342032"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1773344611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1773343355"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1773342205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cli:1773341896"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cli-artifacts:1773345940"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cloud-credential-operator:1773343695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1773339475"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1773343530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-autoscaler:1773332246"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1773341054"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1773341531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-bootstrap:1773345188"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1773340278"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1773340278"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1773344125"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-config-operator:1773342131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1773341257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1773342797"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-dns-operator:1773343883"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1773342823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1773344342"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1773344451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1773368919"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1773344562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1773343261"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1773341839"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1773342046"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-machine-approver:1773344632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1773343953"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-network-operator:1773341222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-node-tuning-operator:1773196318"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1773196318"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-olm-operator-rhel8:1773341005"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1773342109"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1773341529"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1773344624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1773341676"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-samples-operator:1773332230"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-storage-operator:1773341029"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-version-operator:1773344558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-configmap-reloader:1773341005"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-console:1773344549"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-console-operator:1773344209"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1773341458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-coredns:1773339259"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1773339835"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1773338018"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1773340742"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1773344506"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1773344156"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1773340673"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-attacher:1773341570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1773341570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-provisioner:1773343240"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1773343240"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-resizer:1773339440"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1773339440"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1773339534"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1773339534"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-livenessprobe:1773341651"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1773341651"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1773343868"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1773343868"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1773341067"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1773341067"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1773344428"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-docker-builder:1773332824"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-docker-registry:1773343857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-etcd-rhel9:1772163356"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1773335411"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1773337806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1773337076"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1773337665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772163141"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-hypershift-rhel8:1773344697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1773343329"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1773339370"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1773340589"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1773335690"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1773336221"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1773337668"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1773335172"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1773341190"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-installer:1773339664"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-installer-artifacts:1773346692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1773804421"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1773340975"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-proxy:1773341012"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1773343330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-state-metrics:1773340748"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1773341271"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1773344073"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1773332380"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1773343785"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-operator:1773343031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1773335125"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1773335257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1773335660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1773343702"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-config-operator:1773340830"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-admission-controller:1773345383"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-cni:1773343929"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1773343915"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1773332038"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1773332409"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-must-gather:1773345929"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1773345470"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1773343311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel8:1773335046"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1773335146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1773341316"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-proxy:1773332133"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1773341710"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-catalogd-rhel8:1773343230"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel8:1773341572"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1773340708"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1773345444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1773368924"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1773345070"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1773339203"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1773342056"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1773343192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1773345659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-marketplace:1773343023"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-registry:1773343637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1773343313"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes:1773715361"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1773197106"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1773715361"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-pod:1773340839"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1773338014"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1773336904"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1773340072"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1773715250"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus:1773332177"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1773332537"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1773345272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1773332597"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-operator:1773345238"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1773343834"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prom-label-proxy:1773332352"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-sdn-rhel8:1773345987"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-service-ca-operator:1773345575"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-telemeter:1773339555"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-tests:1773351089"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-thanos-rhel8:1773344569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1773335152"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1773335178"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1773335023"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1773334998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1773335152"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1773335178"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1773335060"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1773335032"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1773344275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1773343930"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1772594314"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/egress-router-cni-rhel8:1772594423"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/kube-metrics-server-rhel8:1772594433"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1772594446"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/network-tools-rhel8:1773239872"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772905739"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1772594205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1772905800"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1772595977"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772162408"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1772593853"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772162245"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel9:1772158753"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel9:1772158178"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1772591625"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel9:1772158126"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772161424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772158724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772158379"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772158585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772158500"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772158369"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772158195"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772158148"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772158347"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1772591689"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772158196"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1772591707"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772158204"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel8:1772591720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1772913885"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1773239686"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772161452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772159397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cli:1772593914"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cli-artifacts:1772596250"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cloud-credential-operator:1772594153"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772160439"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772161411"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772159660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772161723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772160918"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772160420"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772161531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772162139"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772161467"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772158371"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772160872"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772158328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772162066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772166357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772459252"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772161328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1773196239"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772162329"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1772158406"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772589902"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772159291"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772161853"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1772160020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772161419"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1773196322"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-olm-operator-rhel8:1772593863"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772501601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772161709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel9:1772161022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772161758"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772158398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772159612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772158422"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772159317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-console:1773067104"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772161537"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1772594559"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-coredns-rhel9:1772545037"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1772593677"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772158231"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772159479"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1772593972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1772158406"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1772162132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772159851"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-provisioner:1772593869"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1772593869"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-resizer:1772593829"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1772593829"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772158390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-livenessprobe:1772593957"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1772593957"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1772594295"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1772594295"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772160726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1772161730"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-docker-builder:1773066913"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772159592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-etcd-rhel9:1772161580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772160388"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772158280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1772593421"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772158664"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772159941"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-hypershift-rhel9:1772158509"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772159729"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772159546"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772160752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1772593433"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772762692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel9:1772159085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1772591753"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772161332"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer:1772913721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer-altinfra-rhel8:1772906451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer-artifacts:1772913731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1773196391"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter-rhel9:1772158362"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772162376"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772161148"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772160887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772158339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772589844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772158407"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772158446"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772159843"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772160521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772158357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-config-operator:1772718370"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772159453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-cni:1772593876"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772160428"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1772590743"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1772590749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-must-gather:1772596248"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1772594128"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772158344"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772158102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772158113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772161645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772160129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772159570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-catalogd-rhel8:1772594220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel8:1772593950"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1772593901"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772718295"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772158341"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772160415"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1772593880"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772160839"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772160426"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel8:1772594146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1772160699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1772161681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1772161581"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1773197106"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1773197167"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-pod-rhel9:1772161626"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1772593753"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772160295"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772158241"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772160348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus:1772590844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1772590779"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772158352"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1772590783"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772162138"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772160722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prom-label-proxy:1772590796"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-sdn-rhel9:1772161632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772162167"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772158296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-tests:1773025638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-thanos-rhel8:1772594576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1772591634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772158737"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772158459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772158076"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1772591634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1772158737"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772158188"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772158726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1772594159"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772159988"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20089",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-dpu-cni-rhel9:1779253503"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1772204773"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1772201426"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1772203718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1772204603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/egress-router-cni-rhel9:1772202565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1772201428"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1772202734"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/network-tools-rhel9:1773196569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772204207"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1772202965"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1772202805"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1772204478"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772202512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1772204220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772202555"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel9:1772201603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel9:1772201405"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772203587"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772201608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772201800"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772201636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772201582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772201466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772201566"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772201620"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772201733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772201692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1772201583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1772201489"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772762650"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1772201619"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1772502485"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1773195263"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772201463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772203453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1772205409"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cli-rhel9:1772203496"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1772201646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772204720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772201483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772201717"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772203756"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772201426"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772204726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772204015"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772205396"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772201497"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772202652"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772204697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772201471"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772201441"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772201713"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772201467"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772203438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772589085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772201484"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1772204568"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772589081"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772204306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772201700"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1773238168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772202518"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1773195351"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1772203041"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772286010"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772204393"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772203933"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772202882"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772204131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772201429"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772201386"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-console-rhel9:1773283464"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772204765"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1772203441"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-coredns-rhel9:1772545388"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772201602"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1772202453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772762720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1772201468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9-operator:1772201430"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1772203949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772202384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1772203816"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1772202824"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772204212"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1772203368"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1772203341"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772205182"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1772201461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1772762811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772201725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-etcd-rhel9:1772202479"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772202442"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772202474"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1772201478"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772201612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772204447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-hypershift-rhel9:1772201570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772202847"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772202271"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772201785"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772762784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1772205614"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1772201554"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772202598"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1772502404"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1772506722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-rhel9:1772506683"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1773281552"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter-rhel9:1772201446"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772203793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772631483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772201460"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772201463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772202825"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772201676"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772201661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772203481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772204047"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772202943"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1772545548"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772201450"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1772204117"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1772202387"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772203531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1772204752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1772202385"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-must-gather-rhel9:1772205322"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1772204587"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772203695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772201477"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772201426"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772203429"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772205425"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772203844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1772203373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1772201461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-rukpak-rhel9:1772202689"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772545401"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772202613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772203909"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772203331"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1772202417"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772201424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1772202662"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1773281200"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1773281156"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1773108630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1773281146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1773195340"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1773152740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-pod-rhel9:1772201525"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772762788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1772202792"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772202431"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772201786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1772201675"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772201470"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1772201521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772202405"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-rhel9:1772202664"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772204871"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1772201567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-sdn-rhel9:1772201800"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772205210"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772201429"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-tests-rhel9:1773281710"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-thanos-rhel9:1772201723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-tools-rhel9:1773195414"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772762616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1772201435"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772201389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772201431"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1772762616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1772201435"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772201642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772201501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772201473"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772202424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1772148780"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1772152031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1772151536"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1772151989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/egress-router-cni-rhel9:1772149192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/frr-rhel9:1772153013"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1772152907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1772149692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/network-tools-rhel9:1773220624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772151718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1772152471"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1772151306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1772152719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772150914"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1772150451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772149419"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772151157"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772143197"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772138217"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772137347"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772137267"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772138198"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772137307"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772137291"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772138198"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772137356"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1772137262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1772138059"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772754185"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1772137272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1772149612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1772710902"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1772152187"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772150980"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772149109"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1772158438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cli-rhel9:1772150322"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1772152192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772151608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772151541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772150789"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772152745"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772152259"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772149063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772149248"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772149021"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772152544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772151925"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772150443"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772152922"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772149432"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772149564"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772152073"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772150466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772148644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772148816"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1773188427"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772559324"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772152777"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772149601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1773039212"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772150778"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1773215392"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1772150279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772194956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772150109"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772148728"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772152592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772150391"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772150107"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772151640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-console-rhel9:1773191098"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772151516"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1772149089"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-coredns-rhel9:1772150496"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772147743"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1772147702"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772754163"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1772150876"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9-operator:1772150222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1772151099"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772149797"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1772148817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1772152344"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772149110"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1772152928"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1772149529"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772150140"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1772150279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1772754244"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772864906"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-etcd-rhel9:1772149957"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772148346"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772148255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1772146364"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772146919"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1772152023"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772151677"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-hypershift-rhel9:1772149636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772151206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772149251"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772137418"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772754150"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1772138093"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1772137312"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772148683"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1772710878"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1772713304"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-rhel9:1772713188"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1772754332"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772151505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772452835"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772149094"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772148742"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772150193"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772138110"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772143190"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772146698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772148990"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772152954"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1772791199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1773190843"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772151837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1772148584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1772149384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772149410"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1772149468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1772152392"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-must-gather-rhel9:1772158321"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1772129339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772149115"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772137257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772137251"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772150011"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772151289"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772151977"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1772152458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1772150767"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772148709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772150903"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772150118"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772149882"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1772158321"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772149849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1772150869"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1773039403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1773039228"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1772152511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1773039451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1773190071"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1773189927"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-pod-rhel9:1772149843"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772754171"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1772146812"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772146062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772146642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1772151461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772290054"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1772150540"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772290075"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-rhel9:1772152731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772290016"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1772152696"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772152337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772150585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-tests-rhel9:1773220642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-thanos-rhel9:1772148747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-tools-rhel9:1773215476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772754155"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1772138097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772138196"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772138080"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1772754155"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1772138097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772143195"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772143184"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772150787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772149085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21658",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-dpu-cni-rhel9:1779781148"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1772155436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1772153348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/azure-service-rhel9-operator:1772154020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1772153837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1772155194"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/egress-router-cni-rhel9:1772154191"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/frr-rhel9:1772155107"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1772153067"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1772155294"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1772153849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1772154993"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/network-tools-rhel9:1772596579"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772153579"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1772155975"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1772154813"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1772153187"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772153390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1772154897"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772154987"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772154492"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772143273"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772144322"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772144286"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772144315"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772147371"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772145345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772148254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772145289"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772145423"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1772145316"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1772145276"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772143339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1772144257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1772156809"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1772159009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1772155017"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772155682"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772155177"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1772158460"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cli-rhel9:1772153764"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1772155142"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772155662"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772155318"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772153535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772154326"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772155108"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772154052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772153602"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772154552"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772154394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772154053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772154174"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772154391"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772153476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772155957"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772153610"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772154594"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772156931"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772153032"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1772154102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772594905"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772155837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772153793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1772153977"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772607635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1772594849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1772154455"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772155044"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772156044"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772155049"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772153649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772153311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772154386"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772155638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9:1772667384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772155949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1772153721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-coredns-rhel9:1772155143"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772151262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1772149658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772149193"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772153223"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1772152995"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1772155003"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772155805"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1772155737"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1772155975"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772153125"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1772156116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1772153323"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772155171"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-etcd-rhel9:1772154146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772150517"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772151005"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1772149626"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772148817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1772155773"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772155487"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hypershift-rhel9:1772153838"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772154801"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772155336"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772154773"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772472660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1772149860"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1772148178"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772233971"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1772165362"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1772165808"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-rhel9:1772165258"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1772496383"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772153451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1772154283"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772155944"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772153307"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772154234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772155547"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772148166"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772147326"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772150797"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772156095"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772153269"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1772666298"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1772650237"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772154094"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1772155206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1772165313"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772153985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1772154567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1772155923"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-must-gather-rhel9:1772158387"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1772154361"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772153757"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772147249"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772143185"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772155737"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772155369"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772153863"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1772153599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1772154150"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772153832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772153695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772153914"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772156040"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1772153761"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772156058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1772154060"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1772155111"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1772153102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1772154380"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1772153026"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1772497726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1772497815"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-pod-rhel9:1772153061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772151748"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1772149956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772149150"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772150903"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1772156477"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772204533"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1772154971"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772204580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9:1772154124"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772205456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1772154933"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772153724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772153990"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tests-rhel9:1772596618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-thanos-rhel9:1772156127"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tools-rhel9:1772595049"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772144208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1772147246"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772144147"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772148047"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772143204"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772146701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772155711"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772155638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1774581842"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1774582041"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/azure-service-rhel9-operator:1774583050"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1774586695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1774582784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/egress-router-cni-rhel9:1774583335"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/frr-rhel9:1774576366"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1774972857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1774582243"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1774583433"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1774582606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/network-tools-rhel9:1775017582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1774582280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1774582490"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1774587461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1774582105"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1774583317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1774584420"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1774587260"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1774584615"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1774578457"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1774579866"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1774578487"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1774578459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1774578439"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1774578512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1774578512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1774578481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1774578512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1774578450"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1774578448"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1774580232"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1774578471"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1774586756"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1774589743"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1774584266"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1774602561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1774584803"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1774588597"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cli-rhel9:1774578276"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1774584317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1774583522"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1774582384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1774914040"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1774587339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1774582760"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1774583174"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1774582786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1774582870"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1774583438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1774587205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1774582358"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1774582754"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1774582243"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1774586684"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1774582802"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1774581961"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1774583185"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1774582722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1774587160"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1774581980"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1774582496"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1774583102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1774583470"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1774583139"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1775013133"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1774581966"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1774582232"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1774583491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1774582934"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1774576259"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1774582551"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1774586701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1774583188"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9:1775029315"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9-operator:1774582951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1774582410"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-coredns-rhel9:1774584507"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1774581730"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1774581751"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1774581021"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1774582014"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1774577822"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1774578369"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1774577908"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1774577738"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1774578083"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1774582798"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1774584392"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1774576360"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1774602653"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-etcd-rhel9:1774584726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1774581686"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1774580947"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1774580998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1774581650"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1774583603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1774583567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hypershift-rhel9:1774584679"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1774584459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1774578432"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1774631216"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1774578470"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1774587063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1774579752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1774587182"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1774605398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1774605414"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-rhel9:1774605357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1774576518"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1774584711"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1774578234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1774582097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1774584584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1774582434"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1774584406"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1774579769"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1774579749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1774581760"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1774582393"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1774602602"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1774584809"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1774265268"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1774582742"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1774582823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1774582884"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1774582077"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1774584767"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1774584113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-must-gather-rhel9:1774580267"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1774584656"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1774582697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1774578453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1774578145"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1774583065"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1774576263"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1774585257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1774584550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1774584090"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1774584623"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1774583436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1774583358"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1774587499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1774582287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1774583042"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1774584311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1775013123"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1775013058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1774582802"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1775013090"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1774587990"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1774588072"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-pod-rhel9:1774584418"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1774581049"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1774581625"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1774581000"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1774581017"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1774602615"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1774583087"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1774583219"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1774582906"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9:1774602650"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1774582556"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1774582857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1774583042"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-telemeter-rhel9:1774584391"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tests-rhel9:1775017577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-thanos-rhel9:1774602652"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tools-rhel9:1775013185"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1774578498"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1774578452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1774578209"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1774578468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1774578498"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1774578452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1774578459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1774578444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1774582583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1774584742"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1552",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hypershift-rhel9:1768607572"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20042",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-dpu-cni-rhel9:1779250418"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1772166986"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1772166701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1772168239"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-service-rhel9-operator:1772167793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1772167733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1772168057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/egress-router-cni-rhel9:1772168448"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/frr-rhel9:1772168092"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1772686533"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1772686690"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1772157106"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1772181061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/network-tools-rhel9:1773220587"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772716787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1772466901"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openstack-resource-controller-rhel9:1772166711"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1772181231"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1772168325"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772167317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1772157328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772166890"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772167008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772150798"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772150820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772149345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772149330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772150705"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772150844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772150771"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772150828"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772149306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1772150731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1772150759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772758175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1772151055"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1772167480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1772169582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1772168208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772167234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772167740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1772168967"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-rhel9:1772167409"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1772168373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772167462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772168176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772167544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772167861"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772167359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772167787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772167838"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772166959"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772167749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772168066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772166968"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772168113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772167859"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772167681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772167936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772157422"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772167226"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772181032"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1772167384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772595132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772168149"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772181009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1772709768"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772181022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1773215644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1772168183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772166718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772168076"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772181016"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772167789"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772477555"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772181012"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772167303"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9:1773096874"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772168220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1772168465"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-coredns-rhel9:1772181028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772154330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1772154031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772758170"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772167160"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1772166820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1772168206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772165961"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1772167933"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1772168079"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772181009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1772732473"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772167583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-etcd-rhel9:1772168302"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772154896"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772155817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1772154368"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772155114"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1772166752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772167456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hypershift-rhel9:1773125843"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772166192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772167204"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772166058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772758129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1772166233"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1772758160"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772165687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1772168742"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-rhel9:1772181272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1773057061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772181213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1772157180"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772167648"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772166097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772165479"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772165468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772151123"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772150802"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772155068"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772686568"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772166247"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1773184042"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1772709791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772165550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1772168198"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1772168446"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772686595"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1772166453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1772157220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-must-gather-rhel9:1772168903"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1772166450"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772165931"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772149183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772150968"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772166205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772167976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772167261"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1772165817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1772166052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772165925"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772166357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772166715"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772165985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1772165440"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772165924"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1772167832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1772595791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1772595334"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1772157323"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1772595900"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1773184641"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1773184785"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-pod-rhel9:1772168337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772758222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1772155094"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772154869"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772153399"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1772168339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772595658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1772168168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772595499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9:1772167208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772595786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1772166706"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772157057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772157116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tests-rhel9:1773220566"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-thanos-rhel9:1772157258"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tools-rhel9:1773215681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772758087"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1772150646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772686584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772150699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1772758087"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1772150646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772150660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772150954"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772166356"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772167335"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1768198703"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1768198857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1768199627"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/azure-service-rhel9-operator:1768203630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1768199574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1768198181"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/egress-router-cni-rhel9:1768201460"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/frr-rhel9:1768203330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1768200492"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1768198483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1768201765"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1768199819"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/network-tools-rhel9:1768209175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1768201937"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1768200424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/openstack-resource-controller-rhel9:1768203133"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1768198699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1768201184"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1768201642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1768200088"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-ui-rhel9:1768198236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1768202895"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1768199585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1768198158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1768198260"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1768198167"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1768198101"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1768198098"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1768198202"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1768198188"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1768198183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1768198133"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1768198148"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1768198038"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1768199009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1768198105"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1768202378"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1768205435"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1768199570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1768202475"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1768202794"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1768204937"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cli-rhel9:1768202909"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1768199629"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1768202763"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1768202307"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1768202357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1768203462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1768199668"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1768199172"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1768203004"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1768200021"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1768198151"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1768199736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1768198243"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1768199989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1768199238"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1768201910"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1768201199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1768200906"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1768200817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1768201252"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1768202025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1768199450"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1768203024"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1768201614"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1768198210"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1768288463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1768248381"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1768200709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1768199737"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1768203178"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1768198798"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1768203197"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1768198419"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1768202028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1768198607"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-console-rhel9:1768199914"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-console-rhel9-operator:1768202404"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1768199236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-coredns-rhel9:1768201092"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1768198368"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1768199199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1768199281"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1768203441"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1768202654"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1768202809"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-snapshot-metadata-rhel9:1768200491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1768200775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1768200870"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1768201151"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1768201542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1768199075"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1768202341"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-etcd-rhel9:1768200282"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1768198154"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1768199388"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1768200306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1768288492"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1768202671"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1768200805"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-hypershift-rhel9:1768265391"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1768200454"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1768198254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1768201845"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1768199284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1768203145"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1768198132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1768200964"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1768205532"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-installer-rhel9:1768205253"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1768198295"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1768200031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1768202948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1768203076"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1768198231"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1768202156"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1768201486"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1768198158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1768198163"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1768200204"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1768198452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1768199413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1768265473"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1768199528"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1768202791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1768198838"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1768202999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1768201557"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1768203195"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1768202688"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-must-gather-rhel9:1768204737"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1768198131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1768199297"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1768244240"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1768198126"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1768202900"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1768201588"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1768199175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1768200400"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1768203186"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1768203339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1768200604"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1768198128"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1768288813"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1768203229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1768198835"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1768199371"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1768203589"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1768199591"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1768202823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1768201498"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1768203756"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1768203729"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-pod-rhel9:1768199992"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1768198725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1768199807"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1768199472"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1768198348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1768200433"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1768202844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1768203249"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1768202692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-rhel9:1768201991"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1768199224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1768201343"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1768202579"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-telemeter-rhel9:1768203481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-tests-rhel9:1768204163"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-thanos-rhel9:1768248393"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-tools-rhel9:1768199136"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1768198163"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1768198134"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1768198281"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1768198166"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1768198232"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1768198150"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1768200744"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1768199119"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0663",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/volume-data-source-validator-rhel9:1768202042"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21704",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-dpu-cni-rhel9:1779777646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1774651955"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20034",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-hypershift-rhel9:1779253332"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2129",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1769729805"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9:1781555717"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9-operator:1781554936"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-core-rhel9:1781555645"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-rhel9-operator:1781556009"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-console-rhel9:1781558423"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-rhel9-operator:1781555708"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1781557202"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-rhel9-operator:1781555679"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cli-rhel9:1781557189"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-console-rhel9:1781556534"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1781556085"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1781555971"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1781557158"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1781556690"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1781558326"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-must-gather-rhel9:1781556544"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-rhel9-operator:1781556958"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odr-rhel9-operator:1781556901"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1781557496"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9:1783676191"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9-operator:1783929816"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-core-rhel9:1784094353"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-rhel9-operator:1784093953"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-console-rhel9:1784094943"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-rhel9-operator:1783676585"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1783676649"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-rhel9-operator:1783676675"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cli-rhel9:1784094299"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-console-rhel9:1784094725"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1783676820"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1783676883"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1783676894"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1784095175"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1783676977"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-must-gather-rhel9:1784093503"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-rhel9-operator:1783677297"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odr-rhel9-operator:1783677345"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1783677533"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9:1776079019"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9-operator:1776706744"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-core-rhel9:1776707205"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-rhel9-operator:1776707231"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-console-rhel9:1776707760"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-rhel9-operator:1776707301"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1776079295"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-rhel9-operator:1776707362"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cli-rhel9:1776707418"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1776707377"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-console-rhel9:1776707947"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1776707456"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1776707526"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1776707526"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1776707945"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1776707569"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-must-gather-rhel9:1776707724"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-rhel9-operator:1776707763"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odr-rhel9-operator:1776707771"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1776079774"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces (RHOSDS) 3.26",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2456",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.26::el9",
        "package": "devspaces/udi-rhel9:1770164598"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.8.0",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23421",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.8::el8",
        "package": "rhosdt/tempo-gateway-opa-rhel8:rhosdt-3.8-1765489209"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.8.0",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23421",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.8::el8",
        "package": "rhosdt/tempo-gateway-rhel8:rhosdt-3.8-1765489125"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.8.0",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23421",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.8::el8",
        "package": "rhosdt/tempo-jaeger-query-rhel8:rhosdt-3.8-1765489074"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.8.0",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23421",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.8::el8",
        "package": "rhosdt/tempo-operator-bundle:rhosdt-3.8-1765906658"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.8.0",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23421",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.8::el8",
        "package": "rhosdt/tempo-query-rhel8:rhosdt-3.8-1765489098"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.8.0",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23421",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.8::el8",
        "package": "rhosdt/tempo-rhel8:rhosdt-3.8-1765489190"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.8.0",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23421",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.8::el8",
        "package": "rhosdt/tempo-rhel8-operator:rhosdt-3.8-1765493403"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.17",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:1018",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.17::el8",
        "package": "openshift-gitops-1/argocd-rhel8:1768825762"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.17",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:1018",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.17::el8",
        "package": "openshift-gitops-1/dex-rhel8:1768825799"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.18",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:1017",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.18::el8",
        "package": "openshift-gitops-1/argocd-rhel8:1768881232"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.18",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:1017",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.18::el8",
        "package": "openshift-gitops-1/dex-rhel8:1768882258"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.19",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1488",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.19::el8",
        "package": "openshift-gitops-1/argocd-rhel8:1769164796"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.19",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1488",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.19::el8",
        "package": "openshift-gitops-1/dex-rhel8:1769166279"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0530",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/istio-cni-rhel8:1767871816"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-01-13T00:00:00Z",
        "advisory": "RHSA-2026:0530",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/pilot-rhel8:1767884649"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3108",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1771390419"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5394",
        "cpe": "cpe:/a:redhat:openstack:17.1::el9",
        "package": "rhosp-rhel9/osp-director-agent:1773255177"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4936",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/prometheus-podman-exporter-rhel9:1771334602"
      },
      {
        "product_name": "Red Hat Quay 3.14",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4215",
        "cpe": "cpe:/a:redhat:quay:3.14::el8",
        "package": "quay/quay-rhel8:1773097621"
      },
      {
        "product_name": "Red Hat Quay 3.15",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1942",
        "cpe": "cpe:/a:redhat:quay:3.15::el8",
        "package": "quay/quay-rhel8:1770146565"
      },
      {
        "product_name": "Red Hat Quay 3.16",
        "release_date": "2025-12-17T00:00:00Z",
        "advisory": "RHSA-2025:23546",
        "cpe": "cpe:/a:redhat:quay:3.16::el9",
        "package": "quay/quay-builder-rhel9:v3.16.0-1765994726"
      },
      {
        "product_name": "Source-to-Image (S2I) 1.5.1",
        "release_date": "2025-11-27T00:00:00Z",
        "advisory": "RHSA-2025:22345",
        "cpe": "cpe:/a:redhat:source_to_image:1.5::el8",
        "package": "source-to-image/source-to-image-rhel8:1.5.2-1764273917"
      },
      {
        "product_name": "Source-to-Image (S2I) 1.5.1",
        "release_date": "2025-11-27T00:00:00Z",
        "advisory": "RHSA-2025:22345",
        "cpe": "cpe:/a:redhat:source_to_image:1.5::el8",
        "package": "source-to-image/source-to-image-rhel9:1.5.2-1764274101"
      }
    ],
    "package_state": [
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "rhai/assisted-installer-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Custom Metric Autoscaler operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
      },
      {
        "product_name": "Deployment Validation Operator",
        "fix_state": "Affected",
        "package_name": "dvo/deployment-validation-rhel8-operator",
        "cpe": "cpe:/a:redhat:deployment_validator_operator"
      },
      {
        "product_name": "external secrets operator for Red Hat OpenShift - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:0"
      },
      {
        "product_name": "Gatekeeper 3",
        "fix_state": "Affected",
        "package_name": "gatekeeper/gatekeeper-rhel9",
        "cpe": "cpe:/a:redhat:gatekeeper:3"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/lokistack-gateway-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/lokistack-gateway-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Migration Toolkit for Applications 7",
        "fix_state": "Affected",
        "package_name": "mta/mta-analyzer-addon-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
      },
      {
        "product_name": "Migration Toolkit for Applications 7",
        "fix_state": "Affected",
        "package_name": "mta/mta-cli-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
      },
      {
        "product_name": "Migration Toolkit for Applications 7",
        "fix_state": "Affected",
        "package_name": "mta/mta-discovery-addon-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
      },
      {
        "product_name": "Migration Toolkit for Applications 7",
        "fix_state": "Affected",
        "package_name": "mta/mta-hub-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-platform-addon-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Will not fix",
        "package_name": "migration-toolkit-virtualization/mtv-api-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-agent-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-service-8-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Will not fix",
        "package_name": "multicluster-engine/backplane-rhel8-operator",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine-capoa-bootstrap-container",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/cluster-proxy-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/hypershift-addon-rhel8-operator",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/hypershift-addon-rhel9-operator",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/hypershift-cli-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/hypershift-cli-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/managedcluster-import-controller-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/managed-serviceaccount-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/multicloud-manager-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/must-gather-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/work-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Affected",
        "package_name": "oadp/oadp-mustgather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Affected",
        "package_name": "oadp/oadp-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Affected",
        "package_name": "oadp/oadp-velero-plugin-for-csi-rhel8",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Affected",
        "package_name": "oadp/oadp-velero-plugin-for-csi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Affected",
        "package_name": "oadp/oadp-velero-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Affected",
        "package_name": "oadp/oadp-velero-rhel8",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "helm",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-jenkins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/openshift-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Will not fix",
        "package_name": "openshift-pipelines-client",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Will not fix",
        "package_name": "openshift-serverless-1/kn-plugin-event-sender-rhel8",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-tech-preview/authorino-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "rhcl-1/authorino-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-search-v2-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multicloud-integrations-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multicluster-operators-channel-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multicluster-operators-subscription-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Affected",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Affected",
        "package_name": "rhel8/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Affected",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Affected",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Affected",
        "package_name": "rhel8/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Affected",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Affected",
        "package_name": "rhel8/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Affected",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Certification for Red Hat Enterprise Linux 8",
        "fix_state": "Out of support scope",
        "package_name": "redhat-certification-preflight",
        "cpe": "cpe:/a:redhat:certifications:1::el8"
      },
      {
        "product_name": "Red Hat Certification Program for Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "redhat-certification-preflight",
        "cpe": "cpe:/a:redhat:certifications:9"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Will not fix",
        "package_name": "3scale-tech-preview/authorino-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Affected",
        "package_name": "rhcl-1/authorino-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Will not fix",
        "package_name": "rhdh-orchestrator-dev-preview-beta/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "rhel10/bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "weldr-client",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "weldr-client",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Will not fix",
        "package_name": "golang",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "microshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/kube-compare-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/metallb-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/metallb-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/numaresources-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/oc-mirror-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-csr-approver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-node-agent-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-node-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-aws-cluster-api-controllers-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-api-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-node-tuning-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-cluster-olm-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-console-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-driver-nfs-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-builder",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-registry",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-dpu-cni-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-helm-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-insights-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-installer",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-api-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-config-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-node-feature-discovery",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-node-feature-discovery-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-olm-catalogd-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-olm-operator-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-olm-rukpak-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-openshift-apiserver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openshift-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-registry",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-sdk-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-sdk-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-prometheus",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ptp",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ptp-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-sriov-network-device-plugin",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-sriov-network-device-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-sriov-network-webhook",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-sriov-network-webhook-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-thanos-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-cloud-controller-manager-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-cluster-api-controllers-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-syncer-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-problem-detector-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ztp-site-generate-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift-clients",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "redhat/redhat-operator-index",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Affected",
        "package_name": "odf4/mcg-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/traefik-rhel8",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/traefik-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/udi-rhel8",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/gitops-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/cluster-network-addons-operator",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Will not fix",
        "package_name": "container-native-virtualization/cluster-network-addons-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/kubevirt-tekton-tasks-create-datavolume-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Will not fix",
        "package_name": "container-native-virtualization/multus-dynamic-networks-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-api-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-cdi-cloner",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-cdi-cloner-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "kubevirt",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "kubevirt-tekton-tasks-test-rhel9-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/osp-director-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-builder-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-operator-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Service Interconnect 2",
        "fix_state": "Not affected",
        "package_name": "skupper-cli",
        "cpe": "cpe:/a:redhat:service_interconnect:2"
      },
      {
        "product_name": "Red Hat Trusted Application Pipeline",
        "fix_state": "Not affected",
        "package_name": "rhtap-task-runner/rhtap-task-runner-rhel9",
        "cpe": "cpe:/a:redhat:trusted_application_pipeline:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/cosign-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-58183\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-58183\nhttps://go.dev/cl/709861\nhttps://go.dev/issue/75677\nhttps://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI\nhttps://pkg.go.dev/vuln/GO-2025-4014"
    ],
    "name": "CVE-2025-58183",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-09-17T17:45:58Z",
    "bugzilla": {
      "description": "rexml: REXML denial of service",
      "id": "2396186",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2396186"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-776",
    "details": [
      "REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.",
      "A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance."
    ],
    "statement": "Red Hat Product Security team has rated this vulnerability as having the 'Moderate' severity, with the final CVSSv3.1 score of 5.3 as the final impact in availability is restricted to the application consuming the REXML package and not the whole system.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23141",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "ruby-0:3.3.10-11.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23927",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "ruby-0:3.3.10-11.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23062",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "ruby:3.3-8100020251124151715.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23063",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "ruby:3.3-9070020251113101221.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-12-11T00:00:00Z",
        "advisory": "RHSA-2025:23140",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "ruby:3.3-9040020251203142310.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23648",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "ruby:3.3-9060020251210162455.9"
      }
    ],
    "package_state": [
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp21/zync",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp22/zync",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp24/zync",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp25/zync",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp26/toolbox",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp26/zync",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/toolbox-rhel7",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/toolbox-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/toolbox-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/zync-rhel7",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/zync-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/zync-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "pcs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "pcs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/kubernetes-nmstate-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-kubernetes-nmstate-handler-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-aodh-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-aodh-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-aodh-evaluator",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-aodh-listener",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-aodh-notifier",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-barbican-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-barbican-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-barbican-keystone-listener",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-barbican-worker",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ceilometer-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ceilometer-central",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ceilometer-compute",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ceilometer-ipmi",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ceilometer-notification",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-cinder-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-cinder-backup",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-cinder-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-cinder-scheduler",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-cinder-volume",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-collectd",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-cron",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-dependencies",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-designate-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-designate-backend-bind9",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-designate-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-designate-central",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-designate-mdns",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-designate-producer",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-designate-sink",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-designate-worker",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-etcd",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-frr",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-glance-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-gnocchi-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-gnocchi-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-gnocchi-metricd",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-gnocchi-statsd",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-haproxy",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-heat-all",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-heat-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-heat-api-cfn",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-heat-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-heat-engine",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-horizon",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ironic-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ironic-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ironic-conductor",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ironic-inspector",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ironic-neutron-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ironic-pxe",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-iscsid",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-keystone",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-manila-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-manila-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-manila-scheduler",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-manila-share",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-mariadb",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-memcached",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-multipathd",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-agent-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-dhcp-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-l3-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-metadata-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-metadata-agent-ovn",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-openvswitch-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-server",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-sriov-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-compute",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-compute-ironic",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-conductor",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-novajoin-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-novajoin-notifier",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-novajoin-server",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-libvirt",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-novncproxy",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-scheduler",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-octavia-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-octavia-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-octavia-health-manager",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-octavia-housekeeping",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-octavia-worker",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ovn-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ovn-bgp-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ovn-controller",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ovn-nb-db-server",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ovn-northd",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ovn-sb-db-server",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-placement-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-qdrouterd",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-rabbitmq",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-redis",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-rsyslog",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-swift-account",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-swift-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-swift-container",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-swift-object",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-swift-proxy-server",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-tempest",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-tripleoclient",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-unbound",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "puppet-agent",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite Client",
        "fix_state": "Fix deferred",
        "package_name": "puppet-agent",
        "cpe": "cpe:/a:redhat:rhel_satellite_client:6::el7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-58767\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-58767\nhttps://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23\nhttps://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5"
    ],
    "name": "CVE-2025-58767",
    "mitigation": {
      "value": "The primary mitigation for this flaw is to avoid parsing XML documents originating from untrusted, unauthenticated, or unverified sources.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-27T08:10:15Z",
    "bugzilla": {
      "description": "dovecot: Dovecot: Information disclosure via specially crafted OOXML documents",
      "id": "2452174",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452174"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-611",
    "details": [
      "Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known.",
      "A flaw was found in Dovecot. An attacker can exploit this by using specially crafted OOXML (Office Open XML) documents that are unsafely handled by a provided script designed for attachment to text conversion. This can lead to unintended files on the system being indexed and subsequently exposed in Full Text Search (FTS) indexes, resulting in information disclosure."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-59031\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-59031\nhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json"
    ],
    "name": "CVE-2025-59031",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-27T08:10:16Z",
    "bugzilla": {
      "description": "dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command",
      "id": "2452172",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452172"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-229",
    "details": [
      "ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.",
      "A flaw was found in ManageSieve. A remote attacker can exploit this vulnerability by sending a crafted SASL (Simple Authentication and Security Layer) initial response during the AUTHENTICATE command. This can cause the ManageSieve service to crash repeatedly, leading to a Denial of Service (DoS) for other users."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13498",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "dovecot-1:2.3.21-16.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19149",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "dovecot-1:2.3.21-19.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17602",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "dovecot-1:2.3.21-16.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26564",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "dovecot-1:2.2.36-8.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13830",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "dovecot-1:2.3.16-7.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19455",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "dovecot-1:2.3.8-9.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19455",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "dovecot-1:2.3.8-9.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19453",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "dovecot-1:2.3.16-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19453",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "dovecot-1:2.3.16-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19453",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "dovecot-1:2.3.16-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18053",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "dovecot-1:2.3.16-3.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18053",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "dovecot-1:2.3.16-3.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13857",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "dovecot-1:2.3.16-15.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19364",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "dovecot-1:2.3.16-18.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17630",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "dovecot-1:2.3.16-3.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17628",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "dovecot-1:2.3.16-8.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17625",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "dovecot-1:2.3.16-11.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17626",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "dovecot-1:2.3.16-15.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-59032\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-59032\nhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json"
    ],
    "name": "CVE-2025-59032",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2025-05-20T00:00:00Z",
    "bugzilla": {
      "description": "libarchive: Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c",
      "id": "2370861",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370861"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.",
      "A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition."
    ],
    "statement": "The Red Hat Product Security team has rated this vulnerability as Important because it allows a local attacker with limited privileges to trigger a double-free in libarchive's RAR parser by providing a specially crafted RAR archive. Successful exploitation could result in code execution or application crashes.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-08-20T00:00:00Z",
        "advisory": "RHSA-2025:14137",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "libarchive-0:3.7.7-4.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2025-08-28T00:00:00Z",
        "advisory": "RHSA-2025:14828",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libarchive-0:3.1.2-14.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-08-20T00:00:00Z",
        "advisory": "RHSA-2025:14135",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "libarchive-0:3.3.3-6.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2025-08-25T00:00:00Z",
        "advisory": "RHSA-2025:14528",
        "cpe": "cpe:/o:redhat:rhel_aus:8.2",
        "package": "libarchive-0:3.3.2-8.el8_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-08-28T00:00:00Z",
        "advisory": "RHSA-2025:14810",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "libarchive-0:3.3.3-1.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2025-08-28T00:00:00Z",
        "advisory": "RHSA-2025:14810",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "libarchive-0:3.3.3-1.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-08-28T00:00:00Z",
        "advisory": "RHSA-2025:14808",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "libarchive-0:3.3.3-6.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-08-28T00:00:00Z",
        "advisory": "RHSA-2025:14808",
        "cpe": "cpe:/o:redhat:rhel_tus:8.6",
        "package": "libarchive-0:3.3.3-6.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-08-28T00:00:00Z",
        "advisory": "RHSA-2025:14808",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.6",
        "package": "libarchive-0:3.3.3-6.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2025-08-25T00:00:00Z",
        "advisory": "RHSA-2025:14525",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "libarchive-0:3.3.3-5.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2025-08-25T00:00:00Z",
        "advisory": "RHSA-2025:14525",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "libarchive-0:3.3.3-5.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-08-20T00:00:00Z",
        "advisory": "RHSA-2025:14130",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libarchive-0:3.5.3-6.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-08-20T00:00:00Z",
        "advisory": "RHSA-2025:14130",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libarchive-0:3.5.3-6.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-08-20T00:00:00Z",
        "advisory": "RHSA-2025:14141",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "libarchive-0:3.5.3-2.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2025-09-02T00:00:00Z",
        "advisory": "RHSA-2025:15024",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libarchive-0:3.5.3-5.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-08-20T00:00:00Z",
        "advisory": "RHSA-2025:14142",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "libarchive-0:3.5.3-4.el9_4.1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2025-10-30T00:00:00Z",
        "advisory": "RHSA-2025:19041",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202510211419-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1541",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202601271320-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0326",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202601071926-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2025-10-22T00:00:00Z",
        "advisory": "RHSA-2025:18218",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202510112152-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2025-10-29T00:00:00Z",
        "advisory": "RHSA-2025:19046",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202510230424-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2025-10-22T00:00:00Z",
        "advisory": "RHSA-2025:18217",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202510140714-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2025-10-21T00:00:00Z",
        "advisory": "RHSA-2025:15397",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "rhcos-4.20.9.6.202509251656-0"
      },
      {
        "product_name": "Red Hat Web Terminal 1.11 on RHEL 9",
        "release_date": "2025-09-15T00:00:00Z",
        "advisory": "RHSA-2025:15828",
        "cpe": "cpe:/a:redhat:webterminal:1.11::el9",
        "package": "web-terminal/web-terminal-rhel9-operator:1.11-19"
      },
      {
        "product_name": "Red Hat Web Terminal 1.11 on RHEL 9",
        "release_date": "2025-09-15T00:00:00Z",
        "advisory": "RHSA-2025:15828",
        "cpe": "cpe:/a:redhat:webterminal:1.11::el9",
        "package": "web-terminal/web-terminal-tooling-rhel9:1.11-8"
      },
      {
        "product_name": "Red Hat Web Terminal 1.12 on RHEL 9",
        "release_date": "2025-09-15T00:00:00Z",
        "advisory": "RHSA-2025:15827",
        "cpe": "cpe:/a:redhat:webterminal:1.12::el9",
        "package": "web-terminal/web-terminal-tooling-rhel9:1.12-4"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-management-console-rhel8:1.36.0-9"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-operator-bundle:1.36.0-12"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-rhel8-operator:1.36.0-18"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7"
      },
      {
        "product_name": "cert-manager operator for Red Hat OpenShift 1.16",
        "release_date": "2025-10-16T00:00:00Z",
        "advisory": "RHSA-2025:18219",
        "cpe": "cpe:/a:redhat:cert_manager:1.16::el9",
        "package": "cert-manager/jetstack-cert-manager-rhel9:v1.16.5-1760515757"
      },
      {
        "product_name": "Compliance Operator 1",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21885",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1::el9",
        "package": "compliance/openshift-compliance-must-gather-rhel8:1.8.0"
      },
      {
        "product_name": "Compliance Operator 1",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21885",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1::el9",
        "package": "compliance/openshift-compliance-openscap-rhel8:1.8.0"
      },
      {
        "product_name": "Compliance Operator 1",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21885",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1::el9",
        "package": "compliance/openshift-compliance-rhel8-operator:1.8.0"
      },
      {
        "product_name": "File Integrity Operator 1",
        "release_date": "2025-11-21T00:00:00Z",
        "advisory": "RHSA-2025:21913",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1::el9",
        "package": "compliance/openshift-file-integrity-rhel8-operator:v1.3"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2025-09-23T00:00:00Z",
        "advisory": "RHSA-2025:16524",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:2.2.1-1758555934"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2025-08-26T00:00:00Z",
        "advisory": "RHSA-2025:14644",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1.5.6-1756187445"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.5.2",
        "release_date": "2025-08-26T00:00:00Z",
        "advisory": "RHSA-2025:14594",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
        "package": "rhosdt/jaeger-agent-rhel8:rhosdt-3.5-1756116455"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.5.2",
        "release_date": "2025-08-26T00:00:00Z",
        "advisory": "RHSA-2025:14594",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
        "package": "rhosdt/jaeger-all-in-one-rhel8:rhosdt-3.5-1756116482"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.5.2",
        "release_date": "2025-08-26T00:00:00Z",
        "advisory": "RHSA-2025:14594",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
        "package": "rhosdt/jaeger-collector-rhel8:rhosdt-3.5-1756116441"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.5.2",
        "release_date": "2025-08-26T00:00:00Z",
        "advisory": "RHSA-2025:14594",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
        "package": "rhosdt/jaeger-es-index-cleaner-rhel8:rhosdt-3.5-1756116449"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.5.2",
        "release_date": "2025-08-26T00:00:00Z",
        "advisory": "RHSA-2025:14594",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
        "package": "rhosdt/jaeger-es-rollover-rhel8:rhosdt-3.5-1756116439"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.5.2",
        "release_date": "2025-08-26T00:00:00Z",
        "advisory": "RHSA-2025:14594",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
        "package": "rhosdt/jaeger-ingester-rhel8:rhosdt-3.5-1756116447"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.5.2",
        "release_date": "2025-08-26T00:00:00Z",
        "advisory": "RHSA-2025:14594",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
        "package": "rhosdt/jaeger-operator-bundle:rhosdt-3.5-1756128595"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.5.2",
        "release_date": "2025-08-26T00:00:00Z",
        "advisory": "RHSA-2025:14594",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
        "package": "rhosdt/jaeger-query-rhel8:rhosdt-3.5-1756125872"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.5.2",
        "release_date": "2025-08-26T00:00:00Z",
        "advisory": "RHSA-2025:14594",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
        "package": "rhosdt/jaeger-rhel8-operator:rhosdt-3.5-1756116445"
      },
      {
        "product_name": "Red Hat OpenShift sandboxed containers 1.1",
        "release_date": "2025-09-11T00:00:00Z",
        "advisory": "RHSA-2025:15709",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1.10::el9",
        "package": "openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9:1.10.2-1757422110"
      },
      {
        "product_name": "Red Hat OpenShift sandboxed containers 1.1",
        "release_date": "2025-09-11T00:00:00Z",
        "advisory": "RHSA-2025:15709",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1.10::el9",
        "package": "openshift-sandboxed-containers/osc-cloud-api-adaptor-webhook-rhel9:1.10.2-1757421846"
      },
      {
        "product_name": "Red Hat OpenShift sandboxed containers 1.1",
        "release_date": "2025-09-11T00:00:00Z",
        "advisory": "RHSA-2025:15709",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1.10::el9",
        "package": "openshift-sandboxed-containers/osc-monitor-rhel9:1.10.2-1757421804"
      },
      {
        "product_name": "Red Hat OpenShift sandboxed containers 1.1",
        "release_date": "2025-09-11T00:00:00Z",
        "advisory": "RHSA-2025:15709",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1.10::el9",
        "package": "openshift-sandboxed-containers/osc-must-gather-rhel9:1.10.2-1757422070"
      },
      {
        "product_name": "Red Hat OpenShift sandboxed containers 1.1",
        "release_date": "2025-09-11T00:00:00Z",
        "advisory": "RHSA-2025:15709",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1.10::el9",
        "package": "openshift-sandboxed-containers/osc-podvm-builder-rhel9:1.10.2-1757421879"
      },
      {
        "product_name": "Red Hat OpenShift sandboxed containers 1.1",
        "release_date": "2025-09-11T00:00:00Z",
        "advisory": "RHSA-2025:15709",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1.10::el9",
        "package": "openshift-sandboxed-containers/osc-podvm-payload-rhel9:1.10.2-1757422401"
      },
      {
        "product_name": "Red Hat OpenShift sandboxed containers 1.1",
        "release_date": "2025-09-11T00:00:00Z",
        "advisory": "RHSA-2025:15709",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1.10::el9",
        "package": "openshift-sandboxed-containers/osc-rhel9-operator:1.10.2-1757421890"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-5914\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-5914\nhttps://github.com/libarchive/libarchive/pull/2598\nhttps://github.com/libarchive/libarchive/releases/tag/v3.8.0"
    ],
    "name": "CVE-2025-5914",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-05-20T00:00:00Z",
    "bugzilla": {
      "description": "libarchive: Integer overflow while reading warc files at archive_read_support_format_warc.c",
      "id": "2370872",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370872"
    },
    "cvss3": {
      "cvss3_base_score": "3.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.",
      "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0."
    ],
    "statement": "This vulnerability is rated Low for Red Hat products as it requires a local attacker to provide a specially crafted WARC archive to an application using libarchive. Successful exploitation could lead to unpredictable program behavior, memory corruption, or an application level denial-of-service condition.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-5916\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-5916\nhttps://github.com/libarchive/libarchive/pull/2568\nhttps://github.com/libarchive/libarchive/releases/tag/v3.8.0"
    ],
    "name": "CVE-2025-5916",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-05-20T00:00:00Z",
    "bugzilla": {
      "description": "libarchive: Off by one error in build_ustar_entry_name() at archive_write_set_format_pax.c",
      "id": "2370874",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370874"
    },
    "cvss3": {
      "cvss3_base_score": "2.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.",
      "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0."
    ],
    "statement": "This vulnerability is rated Low for Red Hat products. The off-by-one error in libarchive can lead to a 1-byte write overflow, potentially causing unpredictable program behavior or crashes. While it could be a building block for more complex exploits, direct exploitation is limited.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-5917\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-5917\nhttps://github.com/libarchive/libarchive/pull/2588\nhttps://github.com/libarchive/libarchive/releases/tag/v3.8.0"
    ],
    "name": "CVE-2025-5917",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-05-20T00:00:00Z",
    "bugzilla": {
      "description": "libarchive: Reading past EOF may be triggered for piped file streams",
      "id": "2370877",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370877"
    },
    "cvss3": {
      "cvss3_base_score": "3.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.",
      "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition."
    ],
    "statement": "This vulnerability is rated Low for Red Hat products. The flaw in libarchive can be triggered when processing specially crafted piped file streams with `bsdtar`, potentially leading to unpredictable program behavior or an application level denial-of-service condition. Exploitation requires user interaction to process a malicious archive.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-5918\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-5918\nhttps://github.com/libarchive/libarchive/pull/2584\nhttps://github.com/libarchive/libarchive/releases/tag/v3.8.0"
    ],
    "name": "CVE-2025-5918",
    "mitigation": {
      "value": "Upgrade to libarchive version 3.8.0 or later, which includes important security fixes and stability improvements.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-01-20T20:41:55Z",
    "bugzilla": {
      "description": "nodejs: Nodejs denial of service",
      "id": "2431349",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431349"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-248",
    "details": [
      "A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that do not attach explicit error handlers to secure sockets, for example:\n```\nserver.on('secureConnection', socket => {\nsocket.on('error', err => {\nconsole.log(err)\n})\n})\n```",
      "A denial of service flaw has been discovered in NodeJS. A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that do not attach explicit error handlers to secure sockets"
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1842",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nodejs24-1:24.13.0-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1843",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nodejs22-1:22.22.0-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2899",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "nodejs22-1:22.22.0-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2420",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nodejs:24-8100020260116121421.6d880403"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2421",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nodejs:22-8100020260119091831.6d880403"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2422",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nodejs:20-8100020260119100525.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2781",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nodejs:24-9070020260117213814.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2782",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nodejs:22-9070020260117213838.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2783",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nodejs:20-9070020260117213748.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2768",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nodejs:20-9040020260211171433.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2767",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nodejs:20-9060020260210180816.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2864",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nodejs:22-9060020260210120402.rhel9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6402",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nodejs24-main-24.14.1-4.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6431",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nodejs25-main-25.9.0-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7386",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nodejs20-main-20.20.0-7.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7387",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nodejs22-main-22.22.0-1.3.hum1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-59465\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-59465\nhttps://nodejs.org/en/blog/vulnerability/december-2025-security-releases"
    ],
    "name": "CVE-2025-59465",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-11-05T00:00:00Z",
    "bugzilla": {
      "description": "libarchive: bsdtar hangs and OOMs with zero-length pattern matches",
      "id": "2412648",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2412648"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-835",
    "details": [
      "An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).",
      "A vulnerability in apply_substitution() function in libarchive's bsdtar allows crafted -s substitution rules to repeatedly match a zero-length substring and append replacements without advancing the input pointer. When the rule uses the global /g flag (or an explicitly empty pattern), this leads to unbounded output allocation and eventual process OOM (Denial of Service). Upgrade to libarchive 3.8.1 or apply a patch that prevents zero-length match loops or rejects empty patterns."
    ],
    "statement": "This vulnerability is rated Moderate rather than Important because its impact is limited to availability and requires user interaction under specific, non-default conditions. Exploitation is only possible when an attacker can directly supply or influence the -s substitution rule passed to bsdtar, which is uncommon in most deployment scenarios since bsdtar is typically invoked with trusted command-line arguments in controlled environments. The flaw does not enable memory corruption, arbitrary code execution, or privilege escalation—it solely results in an infinite loop and memory exhaustion (OOM) leading to a process crash.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8944",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libarchive-main-3.8.7-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-60753\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-60753\nhttps://github.com/Papya-j/CVE/tree/main/CVE-2025-60753\nhttps://github.com/libarchive/libarchive/issues/2725"
    ],
    "name": "CVE-2025-60753",
    "mitigation": {
      "value": "No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-11-10T00:00:00Z",
    "bugzilla": {
      "description": "busybox: BusyBox wget: HTTP request-target allows header injection",
      "id": "2413825",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2413825"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-93",
    "details": [
      "BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).",
      "A flaw was found in BusyBox wget. This vulnerability allows header injection via raw CR/LF and other C0 control bytes in the HTTP request-target. An attacker can exploit this by crafting a URL containing these control characters to inject arbitrary HTTP headers into the outgoing request, potentially leading to HTTP response splitting, cache poisoning, or security policy bypass."
    ],
    "statement": "This issue arises because BusyBox wget fails to sanitize control characters in the request-target before constructing the HTTP/1.1 request line. When wget processes a URL containing raw CR (0x0D), LF (0x0A), or other C0 control bytes, these characters are passed directly into the HTTP request without percent-encoding. This breaks the expected request-line format (METHOD SP request-target SP HTTP/1.1) and allows an attacker to terminate the request line prematurely and inject arbitrary headers on subsequent lines.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7418",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "busybox-main-1.37.0-7.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "busybox",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-60876\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-60876\nhttps://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092\nhttps://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm\nhttps://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm"
    ],
    "name": "CVE-2025-60876",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-30T21:03:08Z",
    "bugzilla": {
      "description": "uri: URI module: Credential exposure via URI + operator",
      "id": "2426336",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2426336"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-212",
    "details": [
      "URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.",
      "A flaw was found in the URI module. A remote attacker could exploit this vulnerability by using the `+` operator to combine Uniform Resource Identifiers (URIs). This bypasses a previous fix and can lead to the leakage of sensitive information, such as user credentials (passwords), from the original URI, resulting in credential exposure."
    ],
    "statement": "This vulnerability is rated Moderate as it allows for credential exposure when the URI module's `+` operator is used to combine URIs. This flaw bypasses a previous fix, potentially leading to sensitive information leakage from the original URI in affected applications across Red Hat Enterprise Linux, OpenShift Container Platform, and other products utilizing the vulnerable URI module.",
    "package_state": [
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "ubi10/ruby-33",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "ruby:3.3/ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "ubi8/ruby-33",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ruby:3.3/ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ubi9/ruby-30",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ubi9/ruby-33",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-61594\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-61594\nhttps://github.com/ruby/uri/commit/20157e3e29b125ff41f1d9662e2e3b1d066f5902\nhttps://github.com/ruby/uri/commit/7e521b2da0833d964aab43019e735aea674e1c2c\nhttps://github.com/ruby/uri/commit/d3116ca66a3b1c97dc7577f9d2d6e353f391cd6a\nhttps://github.com/rubysec/ruby-advisory-db/blob/master/gems/uri/CVE-2025-61594.yml\nhttps://www.ruby-lang.org/en/news/2025/10/07/uri-cve-2025-61594/"
    ],
    "name": "CVE-2025-61594",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-01-28T19:30:31Z",
    "bugzilla": {
      "description": "golang: net/url: Memory exhaustion in query parameter parsing in net/url",
      "id": "2434432",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.",
      "A flaw was found in the net/url package in the Go standard library. The package does not enforce a limit on the number of unique query parameters it parses. A Go application using the net/http.Request.ParseForm method will try to process all parameters provided in the request. A specially crafted HTTP request containing a massive number of query parameters will cause the application to consume an excessive amount of memory, eventually causing the application to crash or become unresponsive, resulting in a denial of service."
    ],
    "statement": "To exploit this flaw, an attacker must be able to send a specially crafted HTTP request to an application parsing URL-encoded forms with net/url, specifically a request containing a large number of unique query parameters. The request will cause the application to consume an excessive amount of memory and eventually result in a denial of service, with no impact to confidentiality or integrity. Due to this reason, this vulnerability has been rated with an important severity.",
    "affected_release": [
      {
        "product_name": "Cryostat 4 on RHEL 9",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3186",
        "cpe": "cpe:/a:redhat:cryostat:4::el9",
        "package": "cryostat/cryostat-grafana-dashboard-rhel9:4.1.1-2"
      },
      {
        "product_name": "Cryostat 4 on RHEL 9",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3186",
        "cpe": "cpe:/a:redhat:cryostat:4::el9",
        "package": "cryostat/cryostat-rhel9-operator:4.1.1-3"
      },
      {
        "product_name": "Cryostat 4 on RHEL 9",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3186",
        "cpe": "cpe:/a:redhat:cryostat:4::el9",
        "package": "cryostat/cryostat-storage-rhel9:4.1.1-3"
      },
      {
        "product_name": "HawtIO HawtIO 4.3.1",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7942",
        "cpe": "cpe:/a:redhat:apache_camel_hawtio:4.3::el9",
        "package": "hawtio-operator-container"
      },
      {
        "product_name": "HawtIO HawtIO 4.4.0",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25089",
        "cpe": "cpe:/a:redhat:apache_camel_hawtio:4.4::el9",
        "package": "hawtio-operator-container"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.4 for RHEL 8",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4460",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.4::el8",
        "package": "receptor-0:1.6.3-4.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.4 for RHEL 9",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4460",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.4::el9",
        "package": "receptor-0:1.6.3-4.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-03-06T00:00:00Z",
        "advisory": "RHSA-2026:3959",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "receptor-0:1.6.3-4.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6278",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "automation-gateway-proxy-0:2.5.10-4.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-03-06T00:00:00Z",
        "advisory": "RHSA-2026:3959",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "receptor-0:1.6.3-4.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6278",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "automation-gateway-proxy-0:2.6.14-1.el9"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 10",
        "release_date": "2026-03-06T00:00:00Z",
        "advisory": "RHSA-2026:3958",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el10",
        "package": "receptor-0:1.6.3-4.el10ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-03-06T00:00:00Z",
        "advisory": "RHSA-2026:3958",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "receptor-0:1.6.3-4.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6277",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "automation-gateway-proxy-0:2.6.14-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2706",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "golang-0:1.25.7-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2914",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "grafana-0:10.2.6-22.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3035",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "grafana-pcp-0:5.3.0-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3092",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "golang-github-openprinting-ipp-usb-0:0.9.27-5.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3297",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "buildah-2:1.41.8-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3336",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "podman-7:5.6.0-12.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3343",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "skopeo-2:1.20.0-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-03T00:00:00Z",
        "advisory": "RHSA-2026:3669",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "go-rpm-macros-0:3.6.0-7.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3752",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "osbuild-composer-0:149-5.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3840",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "image-builder-0:31-4.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3864",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "delve-0:1.25.2-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3971",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "rhc-worker-playbook-0:0.2.3-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4164",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "git-lfs-0:3.6.1-7.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4174",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "opentelemetry-collector-0:0.144.0-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4892",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "rhc-1:0.3.4-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5145",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "yggdrasil-worker-package-manager-0:0.2.3-4.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5146",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "yggdrasil-0:0.4.8-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19013",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "delve-0:1.26.1-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19132",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "rhc-worker-playbook-0:0.2.7-3.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22450",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "osbuild-composer-0:165.1-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22937",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "image-builder-0:52.1-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14868",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "buildah-2:1.39.8-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16696",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "skopeo-2:1.18.1-3.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17040",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "podman-6:5.4.0-15.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17084",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gvisor-tap-vsock-6:0.8.5-2.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3192",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "golang-0:1.25.7-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3506",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "yggdrasil-0:0.4.7-2.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3699",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "yggdrasil-worker-package-manager-0:0.2.3-4.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3813",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "go-rpm-macros-0:3.6.0-5.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3816",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "grafana-pcp-0:5.2.2-4.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3831",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "grafana-0:10.2.6-21.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3843",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "delve-0:1.25.2-2.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3970",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "rhc-worker-playbook-0:0.2.3-3.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3977",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "golang-github-openprinting-ipp-usb-0:0.9.27-3.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4166",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "git-lfs-0:3.6.1-2.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:4256",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "opentelemetry-collector-0:0.144.0-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4907",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "rhc-1:0.3.2-2.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5852",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "osbuild-composer-0:134.1-5.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7676",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "rhc-1:0.2.4-3.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2708",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "go-toolset:rhel8-8100020260212045823.a3795dee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3187",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "grafana-pcp-0:5.1.1-12.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3188",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "grafana-0:9.2.10-28.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3898",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "osbuild-composer-0:101.4-4.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3985",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "git-lfs-0:3.4.1-8.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4672",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "container-tools:rhel8-8100020260311202035.afee755d"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4952",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "rhc-1:0.2.5-4.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3468",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "go-toolset:rhel8-8020020260227115231.02f7cb7a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3841",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "grafana-0:6.3.6-10.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3470",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "go-toolset:rhel8-8040020260227112052.5081a262"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3815",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "grafana-pcp-0:3.0.2-3.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3879",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "grafana-0:7.3.6-12.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3973",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "git-lfs-0:2.13.3-3.el8_4.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5030",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "rhc-1:0.2.0-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5461",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "osbuild-composer-0:28.7-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3470",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "go-toolset:rhel8-8040020260227112052.5081a262"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3815",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "grafana-pcp-0:3.0.2-3.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3879",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "grafana-0:7.3.6-12.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3973",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "git-lfs-0:2.13.3-3.el8_4.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5030",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "rhc-1:0.2.0-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5461",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "osbuild-composer-0:28.7-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19634",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "container-tools:rhel8-8060020260515174849.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3489",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "go-toolset:rhel8-8060020260227122329.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3812",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "grafana-pcp-0:3.2.0-3.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3880",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "grafana-0:7.5.11-9.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3972",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "git-lfs-0:2.13.3-3.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5031",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "rhc-1:0.2.1-13.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51288",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "container-tools:rhel8-8060020260803064027.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5853",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "osbuild-composer-0:46.3-6.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51288",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "container-tools:rhel8-8060020260803064027.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19634",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "container-tools:rhel8-8060020260515174849.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3489",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "go-toolset:rhel8-8060020260227122329.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3812",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "grafana-pcp-0:3.2.0-3.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3880",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "grafana-0:7.5.11-9.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3972",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "git-lfs-0:2.13.3-3.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5031",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "rhc-1:0.2.1-13.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5853",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "osbuild-composer-0:46.3-6.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19634",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "container-tools:rhel8-8060020260515174849.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3489",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "go-toolset:rhel8-8060020260227122329.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3812",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "grafana-pcp-0:3.2.0-3.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3880",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "grafana-0:7.5.11-9.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3972",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "git-lfs-0:2.13.3-3.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5031",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "rhc-1:0.2.1-13.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5853",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "osbuild-composer-0:46.3-6.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3471",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "go-toolset:rhel8-8080020260227110256.6b4b45d8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3821",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "grafana-pcp-0:3.2.0-5.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3838",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "grafana-0:7.5.15-9.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3974",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "git-lfs-0:3.2.0-2.el8_8.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4753",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "osbuild-composer-0:75-7.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49944",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "container-tools:rhel8-8080020260721142025.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5022",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "rhc-1:0.2.2-1.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3471",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "go-toolset:rhel8-8080020260227110256.6b4b45d8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3821",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "grafana-pcp-0:3.2.0-5.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3838",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "grafana-0:7.5.15-9.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3974",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "git-lfs-0:3.2.0-2.el8_8.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4753",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "osbuild-composer-0:75-7.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49944",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "container-tools:rhel8-8080020260721142025.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5022",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "rhc-1:0.2.2-1.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18913",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "containernetworking-plugins-1:1.9.0-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22714",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "osbuild-composer-0:165.1-2.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23228",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "image-builder-0:52.1-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2709",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "golang-0:1.25.7-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2920",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "grafana-0:10.2.6-18.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3040",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "grafana-pcp-0:5.1.1-12.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3291",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "runc-4:1.4.0-2.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3298",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "buildah-2:1.41.8-2.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3337",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "podman-6:5.6.0-14.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3340",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "skopeo-2:1.20.0-3.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3341",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "containernetworking-plugins-1:1.7.1-3.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-03T00:00:00Z",
        "advisory": "RHSA-2026:3668",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "go-rpm-macros-0:3.6.0-13.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3753",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "osbuild-composer-0:149-4.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3839",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "image-builder-0:31-3.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3928",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "git-lfs-0:3.6.1-7.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4177",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "opentelemetry-collector-0:0.144.0-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4901",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "rhc-1:0.2.7-2.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16102",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "buildah-1:1.26.11-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3473",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "golang-0:1.17.13-10.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3822",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "grafana-pcp-0:3.2.0-5.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3854",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "grafana-0:7.5.11-13.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3932",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "git-lfs-0:2.13.3-5.el9_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5079",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "rhc-1:0.2.1-12.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5533",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "osbuild-composer-0:46.3-7.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25248",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "podman-2:4.4.1-22.el9_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25250",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "skopeo-2:1.11.4-0.1.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25251",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "containernetworking-plugins-1:1.2.0-3.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25252",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "buildah-1:1.29.7-1.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25253",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "runc-4:1.2.9-1.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3472",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "golang-0:1.19.13-23.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3820",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "grafana-pcp-0:5.1.1-4.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3836",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "grafana-0:9.0.9-10.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3931",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "git-lfs-0:3.2.0-2.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5076",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "rhc-1:0.2.2-1.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5327",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "osbuild-composer-0:76.1-5.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12028",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "podman-4:4.9.4-20.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12029",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "skopeo-2:1.14.5-2.el9_4.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12030",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "buildah-2:1.33.13-3.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12031",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "runc-4:1.2.9-1.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12032",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "containernetworking-plugins-1:1.4.0-6.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12033",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gvisor-tap-vsock-6:0.7.3-5.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3469",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "golang-0:1.21.13-14.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3818",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "grafana-pcp-0:5.1.1-6.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3835",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "grafana-0:9.2.10-25.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3930",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "git-lfs-0:3.4.1-4.el9_4.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4211",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "osbuild-composer-0:101.3-4.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:4267",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "opentelemetry-collector-0:0.144.0-1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5078",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "rhc-1:0.2.4-6.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11749",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "buildah-2:1.39.6-2.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3193",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "golang-0:1.25.7-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3814",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "go-rpm-macros-0:3.6.0-12.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3817",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "grafana-pcp-0:5.1.1-12.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3833",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "grafana-0:10.2.6-18.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3929",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "git-lfs-0:3.6.1-2.el9_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:4264",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "opentelemetry-collector-0:0.144.0-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5077",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "rhc-1:0.2.7-1.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5544",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "osbuild-composer-0:132.2-5.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7854",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "podman-5:5.4.0-20.el9_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9097",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "runc-4:1.2.9-3.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9098",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "skopeo-2:1.18.1-5.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9108",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gvisor-tap-vsock-6:0.8.5-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9109",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "containernetworking-plugins-1:1.6.2-3.el9_6"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26527",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "containernetworking-plugins-1:1.4.0-6.rhaos4.12.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26527",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "skopeo-2:1.9.4-8.rhaos4.12.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26541",
        "cpe": "cpe:/a:redhat:openshift:4.13::el8",
        "package": "containernetworking-plugins-1:1.4.0-7.rhaos4.13.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26541",
        "cpe": "cpe:/a:redhat:openshift:4.13::el8",
        "package": "podman-3:4.4.1-19.rhaos4.13.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26541",
        "cpe": "cpe:/a:redhat:openshift:4.13::el8",
        "package": "skopeo-2:1.11.3-6.rhaos4.13.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28886",
        "cpe": "cpe:/a:redhat:openshift:4.14::el8",
        "package": "containernetworking-plugins-1:1.4.0-6.rhaos4.14.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28886",
        "cpe": "cpe:/a:redhat:openshift:4.14::el8",
        "package": "podman-3:4.4.1-25.rhaos4.14.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:28961",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "containernetworking-plugins-1:1.4.0-6.rhaos4.15.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10096",
        "cpe": "cpe:/a:redhat:openshift:4.16::el8",
        "package": "containernetworking-plugins-1:1.4.0-8.rhaos4.16.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10096",
        "cpe": "cpe:/a:redhat:openshift:4.16::el8",
        "package": "runc-4:1.2.9-3.rhaos4.16.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10096",
        "cpe": "cpe:/a:redhat:openshift:4.16::el8",
        "package": "skopeo-2:1.14.5-6.rhaos4.16.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17595",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "podman-5:5.2.2-18.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3416",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "containernetworking-plugins-1:1.4.0-7.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3416",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "runc-4:1.2.9-3.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3416",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "skopeo-2:1.16.1-4.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17446",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "podman-5:5.2.2-11.rhaos4.18.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3875",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "containernetworking-plugins-1:1.4.0-7.rhaos4.18.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3875",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "runc-4:1.2.9-4.rhaos4.18.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3875",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "skopeo-2:1.16.1-3.rhaos4.18.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3391",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "runc-4:1.2.5-4.rhaos4.19.el9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3391",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "skopeo-2:1.18.1-4.rhaos4.19.el9"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54757",
        "cpe": "cpe:/a:redhat:openstack:16.2::el8",
        "package": "collectd-sensubility-0:0.2.1-1.1.el8ost"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54757",
        "cpe": "cpe:/a:redhat:openstack:16.2::el8",
        "package": "etcd-0:3.3.23-22.el8ost"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1 for RHEL 9",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:28047",
        "cpe": "cpe:/a:redhat:openstack:17.1::el9",
        "package": "etcd-0:3.4.26-9.5.el9ost"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18.0",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39810",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "golang-github-openstack-k8s-operators-os-diff-0:0.1.1-18.0.20260602234716.a95ae05.el9ost"
      },
      {
        "product_name": "Red Hat Satellite 6.18 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5968",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "yggdrasil-worker-forwarder-0:0.0.3-4.el9sat"
      },
      {
        "product_name": "Streams for Apache Kafka 3.2.0",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13571",
        "cpe": "cpe:/a:redhat:amq_streams:3.2::el9",
        "package": "golang-github-danielqsj-kafka_exporter"
      },
      {
        "product_name": "cert-manager operator for Red Hat OpenShift 1.17",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5645",
        "cpe": "cpe:/a:redhat:cert_manager:1.17::el9",
        "package": "cert-manager/jetstack-cert-manager-acmesolver-rhel9:1774342146"
      },
      {
        "product_name": "cert-manager operator for Red Hat OpenShift 1.17",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5645",
        "cpe": "cpe:/a:redhat:cert_manager:1.17::el9",
        "package": "cert-manager/jetstack-cert-manager-rhel9:1774341716"
      },
      {
        "product_name": "Compliance Operator 1",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8433",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1::el9",
        "package": "compliance/openshift-compliance-operator-bundle:1776237332"
      },
      {
        "product_name": "Custom Metric Autoscaler 2.19",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26636",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2.19::el9",
        "package": "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9:1780101239"
      },
      {
        "product_name": "Custom Metric Autoscaler 2.19",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26636",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2.19::el9",
        "package": "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator:1779953535"
      },
      {
        "product_name": "DevWorkspace Operator 0.4",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5851",
        "cpe": "cpe:/a:redhat:devworkspace:0.40::el9",
        "package": "devworkspace/devworkspace-project-clone-rhel9:1773953548"
      },
      {
        "product_name": "DevWorkspace Operator 0.4",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5851",
        "cpe": "cpe:/a:redhat:devworkspace:0.40::el9",
        "package": "devworkspace/devworkspace-rhel9-operator:1773953459"
      },
      {
        "product_name": "external secrets operator for Red Hat OpenShift 1.0",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40924",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1.0::el9",
        "package": "external-secrets-operator/external-secrets-rhel9:1784113402"
      },
      {
        "product_name": "File Integrity Operator 1",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22627",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1::el9",
        "package": "compliance/openshift-file-integrity-rhel8-operator:1780389566"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.0",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7052",
        "cpe": "cpe:/a:redhat:logging:6.0::el9",
        "package": "openshift-logging/cluster-logging-rhel9-operator:1774549440"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.0",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7052",
        "cpe": "cpe:/a:redhat:logging:6.0::el9",
        "package": "openshift-logging/eventrouter-rhel9:1774879741"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.0",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7052",
        "cpe": "cpe:/a:redhat:logging:6.0::el9",
        "package": "openshift-logging/log-file-metric-exporter-rhel9:1774879689"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.0",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7052",
        "cpe": "cpe:/a:redhat:logging:6.0::el9",
        "package": "openshift-logging/logging-loki-rhel9:1774880815"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.0",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7052",
        "cpe": "cpe:/a:redhat:logging:6.0::el9",
        "package": "openshift-logging/loki-rhel9-operator:1774890842"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.0",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7052",
        "cpe": "cpe:/a:redhat:logging:6.0::el9",
        "package": "openshift-logging/lokistack-gateway-rhel9:1774881157"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.0",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7052",
        "cpe": "cpe:/a:redhat:logging:6.0::el9",
        "package": "openshift-logging/opa-openshift-rhel9:1774881153"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.2",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4500",
        "cpe": "cpe:/a:redhat:logging:6.2::el9",
        "package": "openshift-logging/cluster-logging-rhel9-operator:1772626105"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.2",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4500",
        "cpe": "cpe:/a:redhat:logging:6.2::el9",
        "package": "openshift-logging/eventrouter-rhel9:1772560410"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.2",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4500",
        "cpe": "cpe:/a:redhat:logging:6.2::el9",
        "package": "openshift-logging/log-file-metric-exporter-rhel9:1772560359"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.2",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4500",
        "cpe": "cpe:/a:redhat:logging:6.2::el9",
        "package": "openshift-logging/logging-loki-rhel9:1772821930"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.2",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4500",
        "cpe": "cpe:/a:redhat:logging:6.2::el9",
        "package": "openshift-logging/loki-rhel9-operator:1772457661"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.2",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4500",
        "cpe": "cpe:/a:redhat:logging:6.2::el9",
        "package": "openshift-logging/lokistack-gateway-rhel9:1772557881"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.2",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4500",
        "cpe": "cpe:/a:redhat:logging:6.2::el9",
        "package": "openshift-logging/opa-openshift-rhel9:1772558282"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.3",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4939",
        "cpe": "cpe:/a:redhat:logging:6.3::el9",
        "package": "openshift-logging/cluster-logging-rhel9-operator:1773409902"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.3",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4939",
        "cpe": "cpe:/a:redhat:logging:6.3::el9",
        "package": "openshift-logging/log-file-metric-exporter-rhel9:1773409729"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.3",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4939",
        "cpe": "cpe:/a:redhat:logging:6.3::el9",
        "package": "openshift-logging/logging-loki-rhel9:1773409908"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.3",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4939",
        "cpe": "cpe:/a:redhat:logging:6.3::el9",
        "package": "openshift-logging/loki-rhel9-operator:1773409769"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.3",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4939",
        "cpe": "cpe:/a:redhat:logging:6.3::el9",
        "package": "openshift-logging/lokistack-gateway-rhel9:1773409904"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.3",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4939",
        "cpe": "cpe:/a:redhat:logging:6.3::el9",
        "package": "openshift-logging/opa-openshift-rhel9:1773409854"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift 6.4",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4498",
        "cpe": "cpe:/a:redhat:logging:6.4::el9",
        "package": "openshift-logging/cluster-logging-rhel9-operator:1772551196"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift 6.4",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4498",
        "cpe": "cpe:/a:redhat:logging:6.4::el9",
        "package": "openshift-logging/eventrouter-rhel9:1772551200"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift 6.4",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4498",
        "cpe": "cpe:/a:redhat:logging:6.4::el9",
        "package": "openshift-logging/log-file-metric-exporter-rhel9:1772551127"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift 6.4",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4498",
        "cpe": "cpe:/a:redhat:logging:6.4::el9",
        "package": "openshift-logging/logging-loki-rhel9:1772821835"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift 6.4",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4498",
        "cpe": "cpe:/a:redhat:logging:6.4::el9",
        "package": "openshift-logging/loki-rhel9-operator:1772551354"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift 6.4",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4498",
        "cpe": "cpe:/a:redhat:logging:6.4::el9",
        "package": "openshift-logging/lokistack-gateway-rhel9:1772551201"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift 6.4",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4498",
        "cpe": "cpe:/a:redhat:logging:6.4::el9",
        "package": "openshift-logging/opa-openshift-rhel9:1772551158"
      },
      {
        "product_name": "mirror registry for Red Hat OpenShift 2.0",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28441",
        "cpe": "cpe:/a:redhat:mirror_registry:2.0::el8",
        "package": "openshift/mirror-registry-rhel8:1782177012"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13542",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/backplane-rhel9-operator:1777402015"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13542",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/discovery-rhel9:1776457396"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9848",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el9",
        "package": "multicluster-engine/backplane-rhel9-operator:1775678862"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9848",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el9",
        "package": "multicluster-engine/discovery-rhel9:1776103237"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.7",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5636",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.7::el9",
        "package": "multicluster-engine/backplane-rhel9-operator:1773091107"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.7",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5636",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.7::el9",
        "package": "multicluster-engine/discovery-rhel9:1773091107"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8218",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/backplane-rhel9-operator:1775518980"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8218",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/clusterclaims-controller-rhel9:1774918593"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8218",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/cluster-curator-controller-rhel9:1774913604"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8218",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/cluster-image-set-controller-rhel9:1774913615"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8218",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/discovery-rhel9:1774913711"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8218",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/provider-credential-controller-rhel9:1775231857"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11414",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.9::el9",
        "package": "multicluster-engine/backplane-rhel9-operator:1777132091"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11414",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.9::el9",
        "package": "multicluster-engine/clusterclaims-controller-rhel9:1777140067"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11414",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.9::el9",
        "package": "multicluster-engine/cluster-curator-controller-rhel9:1777160459"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11414",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.9::el9",
        "package": "multicluster-engine/cluster-image-set-controller-rhel9:1777160605"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11414",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.9::el9",
        "package": "multicluster-engine/discovery-rhel9:1776435357"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11414",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.9::el9",
        "package": "multicluster-engine/provider-credential-controller-rhel9:1777160741"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5110",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1773650627"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5110",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1773650767"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5110",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-manager-rhel9:1773650749"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5110",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9:1773649705"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5110",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1773649850"
      },
      {
        "product_name": "Network Observability (NETOBSERV) 1.11.1",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6428",
        "cpe": "cpe:/a:redhat:network_observ_optr:1.11::el9",
        "package": "network-observability/network-observability-cli-rhel9:1773992622"
      },
      {
        "product_name": "Network Observability (NETOBSERV) 1.11.1",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6428",
        "cpe": "cpe:/a:redhat:network_observ_optr:1.11::el9",
        "package": "network-observability/network-observability-ebpf-agent-rhel9:1774887582"
      },
      {
        "product_name": "Network Observability (NETOBSERV) 1.11.1",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6428",
        "cpe": "cpe:/a:redhat:network_observ_optr:1.11::el9",
        "package": "network-observability/network-observability-flowlogs-pipeline-rhel9:1773997913"
      },
      {
        "product_name": "Network Observability (NETOBSERV) 1.11.1",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6428",
        "cpe": "cpe:/a:redhat:network_observ_optr:1.11::el9",
        "package": "network-observability/network-observability-rhel9-operator:1774859742"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-kubevirt-velero-plugin-rhel9:1785177413"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-mustgather-rhel9:1785177359"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-rhel9-operator:1785426166"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-velero-plugin-for-aws-rhel9:1785177325"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-velero-plugin-for-csi-rhel9:1785177350"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-velero-plugin-for-gcp-rhel9:1785426129"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-velero-plugin-for-microsoft-azure-rhel9:1785177322"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-velero-plugin-rhel9:1785177357"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-velero-restic-restore-helper-rhel9:1785177438"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-velero-rhel9:1785180878"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6251",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-kubevirt-velero-plugin-rhel9:1772130870"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6251",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-mustgather-rhel9:1773858961"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6251",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-rhel9-operator:1773932894"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6251",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-velero-plugin-for-aws-rhel9:1773858927"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6251",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-velero-plugin-for-gcp-rhel9:1773858827"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6251",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-velero-plugin-for-legacy-aws-rhel9:1773851998"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6251",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-velero-plugin-for-microsoft-azure-rhel9:1773858935"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6251",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-velero-plugin-rhel9:1773858905"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6251",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-velero-restic-restore-helper-rhel9:1772131148"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6251",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-velero-rhel9:1772131017"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4170",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-hypershift-velero-plugin-rhel9:1771857087"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4170",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-kubevirt-velero-plugin-rhel9:1771857516"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4170",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-mustgather-rhel9:1771857381"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4170",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-non-admin-rhel9:1771856841"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4170",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-rhel9-operator:1771952244"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4170",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-velero-plugin-for-aws-rhel9:1771856984"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4170",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-velero-plugin-for-gcp-rhel9:1771856844"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4170",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-velero-plugin-for-legacy-aws-rhel9:1771857147"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4170",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-velero-plugin-for-microsoft-azure-rhel9:1771856962"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4170",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-velero-plugin-rhel9:1771856850"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4170",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-velero-rhel9:1771857537"
      },
      {
        "product_name": "OpenShift Developer Tools and Services 1.6.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:4270",
        "cpe": "cpe:/a:redhat:source_to_image:1.6::el8",
        "package": "source-to-image/source-to-image-rhel8:1773214142"
      },
      {
        "product_name": "OpenShift Developer Tools and Services 1.6.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:4270",
        "cpe": "cpe:/a:redhat:source_to_image:1.6::el8",
        "package": "source-to-image/source-to-image-rhel9:1773214747"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36873",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/lighthouse-agent-rhel9:1782924920"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36873",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/lighthouse-coredns-rhel9:1782924937"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36873",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/nettest-rhel9:1782926302"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36873",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/subctl-rhel9:1782945263"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36873",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/submariner-gateway-rhel9:1782925247"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36873",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/submariner-globalnet-rhel9:1782925266"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36873",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/submariner-rhel9-operator:1782933193"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36873",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/submariner-route-agent-rhel9:1782925328"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/acm-cli-rhel9:1774915148"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/acm-cluster-permission-rhel9:1775441299"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/acm-governance-policy-addon-controller-rhel9:1774915330"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/acm-governance-policy-framework-addon-rhel9:1774915336"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/acm-volsync-addon-controller-rhel9:1774984227"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/cert-policy-controller-rhel9:1774915173"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/config-policy-controller-rhel9:1774915248"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/governance-policy-propagator-rhel9:1774915333"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/multicloud-integrations-rhel9:1775326442"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/multiclusterhub-rhel9:1774915533"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/multicluster-operators-application-rhel9:1774915538"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/multicluster-operators-channel-rhel9:1775585006"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8229",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/multicluster-operators-subscription-rhel9:1775176904"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25127",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/lighthouse-agent-rhel9:1780204232"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25127",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/lighthouse-coredns-rhel9:1780204249"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25127",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/subctl-rhel9:1780238563"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25127",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/submariner-gateway-rhel9:1780204887"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25127",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/submariner-globalnet-rhel9:1780204696"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25127",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/submariner-rhel9-operator:1780204322"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25127",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/submariner-route-agent-rhel9:1780204631"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36882",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/acm-cli-rhel9:1783350872"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36882",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/acm-governance-policy-addon-controller-rhel9:1783352124"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36882",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/acm-governance-policy-framework-addon-rhel9:1783351609"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36882",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/acm-volsync-addon-controller-rhel9:1783208498"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36882",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/cert-policy-controller-rhel9:1783330172"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36882",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/cluster-backup-rhel9-operator:1782517171"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36882",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/config-policy-controller-rhel9:1783349781"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36882",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/governance-policy-propagator-rhel9:1782862719"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36882",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/multiclusterhub-rhel9:1783329407"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11408",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/volsync-rhel9:1777380373"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13548",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/acm-cli-rhel9:1777138376"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13548",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/acm-governance-policy-addon-controller-rhel9:1776817795"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13548",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/acm-governance-policy-framework-addon-rhel9:1776395605"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13548",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/acm-volsync-addon-controller-rhel9:1777406548"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13548",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/cert-policy-controller-rhel9:1776824009"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13548",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/cluster-backup-rhel9-operator:1777127371"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13548",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/config-policy-controller-rhel9:1776815733"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13548",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/governance-policy-propagator-rhel9:1777141836"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13548",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/multiclusterhub-rhel9:1776693014"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46903",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/multicluster-role-assignment-rhel9:1784133634"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47451",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/multicluster-role-assignment-rhel9:1784133634"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8151",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/lighthouse-agent-rhel9:1774084104"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8151",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/lighthouse-coredns-rhel9:1774086225"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8151",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/subctl-rhel9:1774085848"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8151",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/submariner-gateway-rhel9:1774550350"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8151",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/submariner-globalnet-rhel9:1774550347"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8151",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/submariner-rhel9-operator:1774332596"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8151",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/submariner-route-agent-rhel9:1774550357"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4466",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1773235880"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4466",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-rhel8-operator:1773235880"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4466",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-roxctl-rhel8:1773235880"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4466",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-scanner-rhel8:1772474383"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4466",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-scanner-slim-rhel8:1772474383"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4466",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-scanner-v4-rhel8:1773235880"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4467",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1773235860"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4467",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-rhel8-operator:1773235860"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4467",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-roxctl-rhel8:1773235860"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4467",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-scanner-rhel8:1772473062"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4467",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-scanner-slim-rhel8:1772473062"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4467",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-scanner-v4-rhel8:1773235860"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-03-06T00:00:00Z",
        "advisory": "RHSA-2026:3960",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/receptor-rhel9:1772498155"
      },
      {
        "product_name": "Red Hat Developer Hub 1.8",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3089",
        "cpe": "cpe:/a:redhat:rhdh:1.8::el9",
        "package": "rhdh/rhdh-rhel9-operator:1771440517"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7291",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-26-main-1.26.2-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7385",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-25-main-1.25.9-1.hum1"
      },
      {
        "product_name": "Red Hat Lightspeed (formerly Insights) for Runtimes 1.0",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4220",
        "cpe": "cpe:/a:redhat:lightspeed_for_runtimes:1.0::el9",
        "package": "rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator:1.0.1-1773067492"
      },
      {
        "product_name": "Red Hat Migration Toolkit 1.8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41928",
        "cpe": "cpe:/a:redhat:rhmt:1.8::el8",
        "package": "rhmtc/openshift-migration-controller-rhel8:1783953372"
      },
      {
        "product_name": "Red Hat Migration Toolkit 1.8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41928",
        "cpe": "cpe:/a:redhat:rhmt:1.8::el8",
        "package": "rhmtc/openshift-migration-registry-rhel8:1783914276"
      },
      {
        "product_name": "Red Hat Migration Toolkit 1.8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41928",
        "cpe": "cpe:/a:redhat:rhmt:1.8::el8",
        "package": "rhmtc/openshift-migration-rsync-transfer-rhel8:1783914257"
      },
      {
        "product_name": "Red Hat Migration Toolkit 1.8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41928",
        "cpe": "cpe:/a:redhat:rhmt:1.8::el8",
        "package": "rhmtc/openshift-migration-velero-plugin-for-mtc-rhel8:1783914255"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6429",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1774269698"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6429",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1774855916"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6429",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-manager-rhel9:1774269747"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6429",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9:1774222322"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6429",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1774269709"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6226",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1774245790"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6226",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1773650060"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6226",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-manager-rhel9:1774245716"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6226",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9:1773649712"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6226",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1774362315"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.16",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5807",
        "cpe": "cpe:/a:redhat:openshift_ai:2.16::el8",
        "package": "rhoai/odh-codeflare-operator-rhel8:1774282100"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.16",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5807",
        "cpe": "cpe:/a:redhat:openshift_ai:2.16::el8",
        "package": "rhoai/odh-kf-notebook-controller-rhel8:1774282201"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.16",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5807",
        "cpe": "cpe:/a:redhat:openshift_ai:2.16::el8",
        "package": "rhoai/odh-kuberay-operator-controller-rhel8:1774282134"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.16",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5807",
        "cpe": "cpe:/a:redhat:openshift_ai:2.16::el8",
        "package": "rhoai/odh-notebook-controller-rhel8:1774282170"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9:1776740640"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-data-science-pipelines-operator-controller-rhel9:1776740575"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-kf-notebook-controller-rhel9:1776741537"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-ml-pipelines-api-server-v2-rhel9:1776740726"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-ml-pipelines-driver-rhel9:1776740379"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-ml-pipelines-launcher-rhel9:1776740386"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9:1776740351"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9:1776740366"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-mm-rest-proxy-rhel9:1776743908"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-mod-arch-model-registry-rhel9:1776742141"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-model-controller-rhel9:1776243300"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-modelmesh-runtime-adapter-rhel9:1776768939"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-modelmesh-serving-controller-rhel9:1776767718"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-model-registry-operator-rhel9:1776768333"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-model-registry-rhel9:1776767991"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-notebook-controller-rhel9:1776741479"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-trustyai-service-operator-rhel9:1776243254"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-llama-stack-k8s-operator-rhel9:1780394436"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-llm-d-inference-scheduler-rhel9:1780069327"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-llm-d-routing-sidecar-rhel9:1780069124"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3782",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-codeflare-operator-rhel9:1772093325"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3782",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-rhel9-operator:1772340363"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-data-science-pipelines-argo-argoexec-rhel9:1779123559"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9:1779123511"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-llama-stack-k8s-operator-rhel9:1778765413"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-llm-d-inference-scheduler-rhel9:1778263962"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-llm-d-routing-sidecar-rhel9:1778262829"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3713",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-kube-auth-proxy-rhel9:1771440835"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-data-science-pipelines-operator-controller-rhel9:1782810474"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-ml-pipelines-api-server-v2-rhel9:1782813471"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-ml-pipelines-driver-rhel9:1782813281"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-ml-pipelines-launcher-rhel9:1782813457"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9:1782813746"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9:1782813288"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.6.4",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5549",
        "cpe": "cpe:/a:redhat:openshift_builds:1.6::el9",
        "package": "openshift-builds/openshift-builds-controller-rhel9:1773920797"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.6.4",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5549",
        "cpe": "cpe:/a:redhat:openshift_builds:1.6::el9",
        "package": "openshift-builds/openshift-builds-git-cloner-rhel9:1773920861"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.6.4",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5549",
        "cpe": "cpe:/a:redhat:openshift_builds:1.6::el9",
        "package": "openshift-builds/openshift-builds-image-bundler-rhel9:1773921337"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.6.4",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5549",
        "cpe": "cpe:/a:redhat:openshift_builds:1.6::el9",
        "package": "openshift-builds/openshift-builds-image-processing-rhel9:1773921036"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.6.4",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5549",
        "cpe": "cpe:/a:redhat:openshift_builds:1.6::el9",
        "package": "openshift-builds/openshift-builds-rhel9-operator:1774304869"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.6.4",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5549",
        "cpe": "cpe:/a:redhat:openshift_builds:1.6::el9",
        "package": "openshift-builds/openshift-builds-shared-resource-rhel9:1773931994"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.6.4",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5549",
        "cpe": "cpe:/a:redhat:openshift_builds:1.6::el9",
        "package": "openshift-builds/openshift-builds-shared-resource-webhook-rhel9:1773931788"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.6.4",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5549",
        "cpe": "cpe:/a:redhat:openshift_builds:1.6::el9",
        "package": "openshift-builds/openshift-builds-waiters-rhel9:1774334066"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.6.4",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5549",
        "cpe": "cpe:/a:redhat:openshift_builds:1.6::el9",
        "package": "openshift-builds/openshift-builds-webhook-rhel9:1773921206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1777002694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/egress-router-cni-rhel8:1777001625"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1777001562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/network-tools-rhel8:1777002936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1777042122"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1777001567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1777002279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1777002206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel8:1777001821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1777002716"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1777001811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1777001595"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1777001647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1777001622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1777001637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1777001993"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1777002058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1777001588"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1777002145"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1777001819"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1777001657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1777001578"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1777002721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1777001896"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1777001576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1777001621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1777001630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cli:1776999989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cli-artifacts:1777002317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cloud-credential-operator:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1777002062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1777001657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-autoscaler:1777001639"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1777001616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1777001722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-bootstrap:1777001579"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1777001660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1777001660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1777001584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-config-operator:1777001860"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1777001588"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-dns-operator:1777001846"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1777001876"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1777001943"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1777001611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1777001561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1777001575"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1777001571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1777002164"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-machine-approver:1777001580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1777001813"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-network-operator:1777001698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-node-tuning-operator:1777002719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1777001569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1777001603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1777001612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1777001775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-samples-operator:1777001570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-storage-operator:1777001574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-version-operator:1777001558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-configmap-reloader:1777001608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-console:1777002039"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-console-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1777001571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-coredns:1777001653"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1777001577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1777001777"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1777001621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1777001656"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1777001606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-attacher:1777001646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1777001646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-provisioner:1776999972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1776999972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-resizer:1776999948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1776999948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1776999951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1776999951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-livenessprobe:1776999947"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1776999947"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1776999949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1776999949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1777001741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1777001741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1777001992"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-docker-builder:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-docker-registry:1777001681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-etcd:1777001596"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1777001898"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1777002697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1777001692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1777001837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-hyperkube:1777304752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-hypershift-rhel8:1777001784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1777001854"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1777001574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1777001888"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1777001586"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1777001561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1777002168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1777001585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-installer:1777000374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-installer-artifacts:1777003222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1777001763"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1777001618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-proxy:1777001642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1776999981"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-state-metrics:1777001815"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1777001549"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1777001541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1777001647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1777001659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1777001636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1777001608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1777001598"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-config-operator:1777002732"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-admission-controller:1777001535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-cni:1777001584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1777001612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1777001628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1777001576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-must-gather:1777000645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1777002718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1777001624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-proxy:1777001606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1777002057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1777002697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1777002725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1777001617"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1777001581"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1777001775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1777001580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1777001618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-machine-controllers:1777001573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1777001630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-marketplace:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-registry:1777001671"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1777001649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovn-kubernetes:1777002178"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel8:1777001818"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-pod:1777304565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1777001521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1777001566"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1777001771"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1777042146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus:1777001745"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1777001893"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1777002720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1777001726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prom-label-proxy:1777001535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-sdn-rhel8:1777001790"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-service-ca-operator:1777001589"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-telemeter:1777001614"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-tests:1777002345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-thanos-rhel8:1777001839"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1777001605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1777001655"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1777001573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1777001605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1777001823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1777001631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1777001640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1777001645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-08T00:00:00Z",
        "advisory": "RHSA-2026:14100",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-tests:1778173182"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1779864120"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/egress-router-cni-rhel8:1779864235"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1779864128"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/network-tools-rhel8:1779313037"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1779889676"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1779889641"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1778765353"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1778765274"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel8:1779889723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1779863997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1779864079"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1779864508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1779864192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1779889720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1779863999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1779889660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1779889680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1779863969"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1779864074"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1779863989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1779889642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1779863994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1779864633"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1779864005"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1779889629"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1779889720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1779864603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1779863994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1779864132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1779864485"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cli:1779889704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cli-artifacts:1778765373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cloud-credential-operator:1779864236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1779889678"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1779864074"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-autoscaler:1779863413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1779864513"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1779864055"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-bootstrap:1779864189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1779864740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1779864740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1779864043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-config-operator:1779863993"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1779863952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1779864018"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-dns-operator:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1779863985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1779864123"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1779864006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1779863976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1779864264"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1779889616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1779889647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1779864436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-machine-approver:1779864047"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1779864102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-network-operator:1779889634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1779890827"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1779864733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1779864442"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1779864212"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1779889609"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-samples-operator:1779863398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-storage-operator:1779864003"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-version-operator:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-configmap-reloader:1779863974"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-console:1779864415"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-console-operator:1779889659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-coredns:1779864040"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1779889631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1779864020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1779864063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1779863966"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1779863998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1779864441"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-attacher:1779871348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1779871348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-provisioner:1779864793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1779864793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-resizer:1779864022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1779864022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1779864025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1779864025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-livenessprobe:1779864161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1779864161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1779864052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1779864052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1779889611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1779889611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1779889636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-docker-builder:1779863452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-docker-registry:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-etcd-rhel9:1779890788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1779864509"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1779864100"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1779889604"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1779863996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-hyperkube:1779864503"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-hypershift-rhel8:1779864639"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1779889658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1779864019"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1779889649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1779889642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1779864104"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1779863998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1779864066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1779864162"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-installer:1779864501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-installer-artifacts:1778766542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1779890216"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1779864028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-proxy:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1779889644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-state-metrics:1779864165"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1779889585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1779864651"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1779863394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1779864348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-operator:1779864206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1779864736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1779864245"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1779864151"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1779864229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-config-operator:1779864726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-admission-controller:1779864390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-cni:1779864023"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1779889657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1779863412"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1779863416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-must-gather:1778765257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1779864053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1779864236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel8:1779889646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1779864046"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1779864015"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-proxy:1779863392"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1779889638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1779889640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1779889694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1779863972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1779863952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1779864222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1779889602"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1779863995"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1779889649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-marketplace:1779864043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-registry:1779864451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1779864238"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes:1779891613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1779891537"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1779891613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-pod:1779864280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1779863962"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1779864153"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1779864168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1779864213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus:1779863444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1779863390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1779863389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-operator:1779864228"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1779864564"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prom-label-proxy:1779863397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-sdn-rhel8:1778765374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-service-ca-operator:1779864304"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-telemeter:1779889631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-tests:1779313164"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-thanos-rhel8:1779889664"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1779864199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1779864192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1779864001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1779864199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1779889644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1779864320"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1779889619"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1779889628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1777996897"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/egress-router-cni-rhel8:1777997332"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1777997462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/network-tools-rhel8:1778172521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1777997277"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1777996424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1777998220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1777997994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1777472634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1777996679"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1777472583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1777995469"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1777995698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1777995577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1777995808"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1777996402"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1777995599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1777995887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1777995699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1777995687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1777995600"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1777995569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1777995734"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1777995625"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1777995883"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1777995596"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1777995524"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1777995841"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel8:1777995603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1777996820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1777996330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1777997707"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1777997365"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cli:1777995604"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cli-artifacts:1777998025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cloud-credential-operator:1777996333"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1777996553"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1777995495"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-autoscaler:1777994910"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1777996723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1777997379"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-bootstrap:1777995458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1777997008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1777997008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1777996635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-config-operator:1777996776"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1777996381"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1777995506"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-dns-operator:1777995455"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1777996270"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1777996851"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1777996687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1777995760"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1777996782"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1777997020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1777997255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1777997210"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-machine-approver:1777995462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1777996292"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-network-operator:1778112812"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-node-tuning-operator:1777994001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1777994001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-olm-operator-rhel8:1777996262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1777997116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1777996254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1777996661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1777996509"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-samples-operator:1777994956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-storage-operator:1777997078"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-version-operator:1777997456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-configmap-reloader:1777996314"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-console:1777997704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-console-operator:1777997124"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1777997840"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-coredns:1777997281"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1777996831"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1777995492"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1777996366"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1777996486"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1777997218"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1777997375"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-attacher:1777995459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1777995459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-provisioner:1777995632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1777995632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-resizer:1777995652"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1777995652"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1777995784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1777995784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-livenessprobe:1777995463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1777995463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1777995491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1777995491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1777996342"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1777996342"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1777996315"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-docker-builder:1777995244"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-docker-registry:1777997725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-etcd-rhel9:1776786823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1777996755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1777996622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1777996228"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1777996220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1777472765"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-hypershift-rhel8:1778036600"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1777997038"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1777995572"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1777997296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1777995692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1777995653"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1777995573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1777995620"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1777996408"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-installer:1777996107"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-installer-artifacts:1778000857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1777994224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1777996885"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-proxy:1777995592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1777995480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-state-metrics:1777996287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1777996488"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1777997010"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1777994887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1777995962"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-operator:1777995710"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1777995601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1777995701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1777995520"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1777996613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-config-operator:1777997630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-admission-controller:1777997528"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-cni:1778170887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1777997407"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1777995116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1777995224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-must-gather:1777996785"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1777997235"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1777995460"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel8:1777995466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1777995484"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1777996597"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-proxy:1777995007"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1777997297"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-catalogd-rhel8:1777997176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel8:1777997205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1777997362"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1777997248"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1777995735"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1777997139"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1777997025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1777995629"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1777997265"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1777996400"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-marketplace:1777995482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-registry:1777995486"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1777997306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes:1778171006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1777950765"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1778171006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-pod:1777997313"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1777995498"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1777996700"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1777996514"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1777996741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus:1777995270"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1777994952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1777996409"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1777994918"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-operator:1777996333"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1777996709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prom-label-proxy:1777995205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-sdn-rhel8:1777998130"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-service-ca-operator:1777997562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-telemeter:1777997512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-tests:1777998461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-thanos-rhel8:1777996367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1777995461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1777995788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1777995630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1777995475"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1777995461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1777995788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1777995476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1777995464"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1777996582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1777997544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1777994657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/egress-router-cni-rhel8:1777994713"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/kube-metrics-server-rhel8:1777994576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1777994721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/network-tools-rhel8:1777998170"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1777519481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1777994523"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1777998000"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1777997820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1777478482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1777994504"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1777478234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel9:1777474101"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel9:1777474453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1777994483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel9:1777474227"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1777478096"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1777474127"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1777474416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1777474148"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1777474264"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1777474194"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1777474161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1777474315"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1777474158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1777994816"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1777474287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1777994712"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1777474440"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel8:1777994558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1778004053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1777518447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1777518423"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1777518340"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cli:1777994701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cli-artifacts:1777997939"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cloud-credential-operator:1777994673"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1777519328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1777519214"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1777518746"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1777518033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1777518321"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1777519394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1777519372"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1777518060"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1777478520"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1777519262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1777518061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1777478138"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1777519268"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1777518531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1777518280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1777519397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1777478065"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1777518472"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1777518634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1777518054"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1777518444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1777478122"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1777518753"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1778101510"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1777993307"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-olm-operator-rhel8:1777994508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1777518628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1777519168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel9:1777518056"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1777518330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1777519183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1777518052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1777518379"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1777478476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-console:1777994748"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-console-rhel9-operator:1777518836"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1777994759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-coredns-rhel9:1777518907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1777994680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1777476627"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1777477028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1777994803"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1777518277"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1777478042"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1777478430"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-provisioner:1777994744"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1777994744"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-resizer:1777994749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1777994749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1777474331"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-livenessprobe:1777994942"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1777994942"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1777994483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1777994483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1777518734"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1777518257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-docker-builder:1777993865"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1777518560"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-etcd-rhel9:1776790621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1777476910"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1777477747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1777994733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1777477500"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1777519044"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-hypershift-rhel9:1777560403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1777519438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1777474125"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1777474278"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1777994563"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1777474357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel9:1777474345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1777994558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1777518743"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer:1778003878"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer-altinfra-rhel8:1777995426"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer-artifacts:1778003967"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1777993546"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter-rhel9:1777478078"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1777519369"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1777994806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1777518797"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1777518058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1777518288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1777993309"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1777474219"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1777474262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1777477119"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1777518088"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1777519221"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-config-operator:1777994925"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1777478301"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-cni:1777994726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1777519086"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1777993775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1777993779"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-must-gather:1777995829"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1777994575"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1777519043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1777474308"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1777474367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1777518060"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1777518740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1777542478"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-catalogd-rhel8:1777994525"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel8:1777995008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1777994685"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1777518479"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1777518376"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1777519359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1777994467"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1777519284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1777519438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel8:1777994805"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1777545280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1777518048"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1777518565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1777950961"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1777951025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-pod-rhel9:1777518607"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1777994861"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1777476821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1777476388"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1777477330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus:1777993863"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1777993798"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1777478113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1777993796"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1777478254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1777518755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prom-label-proxy:1777993793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-sdn-rhel9:1777518582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1777478120"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-telemeter-rhel9:1777518059"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-tests:1777998234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-thanos-rhel8:1777994557"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1777994462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1777474367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1777474390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1777474189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1777994462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1777474367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1777474311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1777474366"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1777994505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1777478134"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1776727891"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1776699297"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1776728824"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1776727904"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/egress-router-cni-rhel9:1776698563"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1776698624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1776699337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/network-tools-rhel9:1776731043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1776728960"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1776698978"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1776728421"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1776728312"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1776699634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1776699073"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1776728900"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel9:1776697731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel9:1776697719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1776728874"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1776697791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1776697844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1776697799"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1776697771"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1776697837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1776697806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1776697826"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1776697897"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1776697818"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1776697884"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1776697747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1776698735"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1776697825"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1776731113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1776698623"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1776728462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1776699205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1776728072"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cli-rhel9:1776697824"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1776782168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1776698632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1776728357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1776697163"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1776728167"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1776698905"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1776699430"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1776729175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1776699431"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1776699567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1776728154"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1776727801"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1776729050"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1776698337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1776729221"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1776699025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1776728759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1776727905"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1776728036"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1776727910"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1776699521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1776698913"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1776728010"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1776728853"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1776698638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1776729344"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1776728572"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1776728832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1776728728"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1776729115"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1776697180"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1776698874"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1776699128"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1776699189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-console-rhel9:1776827996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-console-rhel9-operator:1776698489"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1776728544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-coredns-rhel9:1776728186"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1776698522"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1776698476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1776698326"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1776729216"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9-operator:1776729099"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1776698985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1776729115"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1776697827"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1776697832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1776697815"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1776697847"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1776697751"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1776729182"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1776698953"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1776697230"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1776728148"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-etcd-rhel9:1776728306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1776698867"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1776698923"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1776698411"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1776698860"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1776728691"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-hypershift-rhel9:1776699376"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1776699740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1776699171"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1776699502"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1776698051"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1776697914"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1776697838"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1776699264"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1776729530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1776734891"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-rhel9:1776734824"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1776827300"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter-rhel9:1776728619"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1776728364"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1776697847"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1776727790"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1776699541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1776698615"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1776729041"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1776697851"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1776697847"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1776698490"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1776699411"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1776699226"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1776699250"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1776698529"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1776698678"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1776698674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1776699303"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1776698645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1776698545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-must-gather-rhel9:1776698851"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1776698463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1776699089"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1776697723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1776697725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1776727937"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1776697196"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1776699112"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1776698518"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1776727948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-rukpak-rhel9:1776728796"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1776698402"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1776728576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1776727924"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1776727875"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1776728631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1776699637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1776699410"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1776729034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1776699635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1776728529"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1776728041"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1776869755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1776869821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-pod-rhel9:1776729175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1776698970"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1776698927"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1776698929"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1776698339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1776699552"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1776698599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1776699247"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1776729049"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-rhel9:1776699050"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1776699182"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1776699224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-sdn-rhel9:1776699232"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1776699071"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-telemeter-rhel9:1776728887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-tests-rhel9:1776728272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-thanos-rhel9:1776728595"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-tools-rhel9:1776697962"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1776697733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1776697721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1776697724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1776697756"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1776697733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1776697721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1776697723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1776697728"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1776727833"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1776729097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1778711747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1778711793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1778707549"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1772148780"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1772152031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1772151536"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1772151989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/egress-router-cni-rhel9:1772149192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/frr-rhel9:1772153013"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1772152907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1772149692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/network-tools-rhel9:1773220624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772151718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1772152471"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1772151306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1772152719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772150914"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1772150451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772149419"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772151157"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772143197"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772138217"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772137347"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772137267"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772138198"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772137307"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772137291"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772138198"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772137356"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1772137262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1772138059"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772754185"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1772137272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1772149612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1772710902"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1772152187"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772150980"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772149109"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1772158438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cli-rhel9:1772150322"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1772152192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772151608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772151541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772150789"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772152745"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772152259"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772149063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772149248"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772149021"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772152544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772151925"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772150443"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772152922"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772149432"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772149564"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772152073"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772150466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772148644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772148816"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1773188427"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772559324"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772152777"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772149601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1773039212"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772150778"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1773215392"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1772150279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772194956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772150109"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772148728"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772152592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772150391"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772150107"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772151640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-console-rhel9:1773191098"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772151516"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1772149089"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-coredns-rhel9:1772150496"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772147743"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1772147702"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772754163"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1772150876"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9-operator:1772150222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1772151099"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772149797"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1772148817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1772152344"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772149110"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1772152928"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1772149529"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772150140"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1772150279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1772754244"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772864906"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-etcd-rhel9:1772149957"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772148346"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772148255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1772146364"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772146919"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1772152023"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772151677"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-hypershift-rhel9:1772149636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772151206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772149251"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772137418"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772754150"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1772138093"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1772137312"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772148683"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1772710878"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1772713304"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-rhel9:1772713188"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1772754332"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772151505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772452835"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772149094"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772148742"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772150193"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772138110"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772143190"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772146698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772148990"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772152954"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1772791199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1773190843"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772151837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1772148584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1772149384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772149410"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1772149468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1772152392"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-must-gather-rhel9:1772158321"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1772129339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772149115"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772137257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772137251"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772150011"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772151289"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772151977"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1772152458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1772150767"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772148709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772150903"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772150118"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772149882"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1772158321"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772149849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1772150869"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1773039403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1773039228"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1772152511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1773039451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1773190071"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1773189927"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-pod-rhel9:1772149843"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772754171"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1772146812"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772146062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772146642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1772151461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772290054"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1772150540"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772290075"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-rhel9:1772152731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772290016"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1772152696"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772152337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772150585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-tests-rhel9:1773220642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-thanos-rhel9:1772148747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-tools-rhel9:1773215476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772754155"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1772138097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772138196"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772138080"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1772754155"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1772138097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772143195"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772143184"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772150787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772149085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4511",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-container-rhel9:1772754561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4511",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-rhel9-operator:1773214876"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4511",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-clusterresourceoverride-rhel9:1772151184"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4511",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-clusterresourceoverride-rhel9-operator:1772152176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4511",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-filestore-csi-driver-rhel9:1772754181"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4511",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-local-storage-diskmaker-rhel9:1773188538"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4511",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-local-storage-mustgather-rhel9:1773188504"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4511",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-local-storage-rhel9-operator:1773188432"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4511",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9:1772151361"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4511",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9-operator:1772148918"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4511",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vertical-pod-autoscaler-rhel9:1772148767"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4511",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vertical-pod-autoscaler-rhel9-operator:1772151213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1779786992"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1779779787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1779779596"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1772155436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1772153348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/azure-service-rhel9-operator:1772154020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1772153837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1772155194"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/egress-router-cni-rhel9:1772154191"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/frr-rhel9:1772155107"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1772153067"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1772155294"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1772153849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1772154993"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/network-tools-rhel9:1772596579"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772153579"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1772155975"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1772154813"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1772153187"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772153390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1772154897"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772154987"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772154492"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772143273"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772144322"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772144286"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772144315"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772147371"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772145345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772148254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772145289"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772145423"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1772145316"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1772145276"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772143339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1772144257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1772156809"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1772159009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1772155017"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772155682"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772155177"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1772158460"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cli-rhel9:1772153764"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1772155142"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772155662"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772155318"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772153535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772154326"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772155108"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772154052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772153602"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772154552"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772154394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772154053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772154174"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772154391"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772153476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772155957"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772153610"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772154594"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772156931"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772153032"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1772154102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772594905"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772155837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772153793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1772153977"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772607635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1772594849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1772154455"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772155044"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772156044"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772155049"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772153649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772153311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772154386"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772155638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9:1772667384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772155949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1772153721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-coredns-rhel9:1772155143"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772151262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1772149658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772149193"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772153223"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1772152995"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1772155003"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772155805"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1772155737"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1772155975"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772153125"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1772156116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1772153323"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772155171"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-etcd-rhel9:1772154146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772150517"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772151005"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1772149626"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772148817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1772155773"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772155487"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hypershift-rhel9:1772153838"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772154801"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772155336"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772154773"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772472660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1772149860"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1772148178"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772233971"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1772165362"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1772165808"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-rhel9:1772165258"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1772496383"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772153451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1772154283"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772155944"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772153307"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772154234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772155547"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772148166"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772147326"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772150797"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772156095"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772153269"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1772666298"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1772650237"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772154094"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1772155206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1772165313"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772153985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1772154567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1772155923"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-must-gather-rhel9:1772158387"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1772154361"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772153757"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772147249"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772143185"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772155737"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772155369"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772153863"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1772153599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1772154150"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772153832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772153695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772153914"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772156040"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1772153761"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772156058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1772154060"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1772155111"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1772153102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1772154380"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1772153026"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1772497726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1772497815"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-pod-rhel9:1772153061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772151748"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1772149956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772149150"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772150903"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1772156477"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772204533"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1772154971"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772204580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9:1772154124"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772205456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1772154933"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772153724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772153990"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tests-rhel9:1772596618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-thanos-rhel9:1772156127"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tools-rhel9:1772595049"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772144208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1772147246"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772144147"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772148047"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772143204"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772146701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772155711"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3905",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772155638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3906",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-container-rhel9:1772144253"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3906",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-rhel9-operator:1772592922"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3906",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-clusterresourceoverride-rhel9:1772154950"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3906",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-clusterresourceoverride-rhel9-operator:1772154573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3906",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-filestore-csi-driver-rhel9:1772149594"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3906",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-local-storage-diskmaker-rhel9:1772234014"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3906",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-local-storage-mustgather-rhel9:1772233991"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3906",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-local-storage-rhel9-operator:1772233973"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3906",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9:1772155688"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3906",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9-operator:1772155883"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3906",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vertical-pod-autoscaler-rhel9:1772153287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3906",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vertical-pod-autoscaler-rhel9-operator:1772155340"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6554",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1774583603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1779252756"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1779250066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1779249713"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1772166986"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1772166701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1772168239"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-service-rhel9-operator:1772167793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1772167733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1772168057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/egress-router-cni-rhel9:1772168448"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/frr-rhel9:1772168092"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1772686533"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1772686690"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1772157106"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1772181061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/network-tools-rhel9:1773220587"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772716787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1772466901"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openstack-resource-controller-rhel9:1772166711"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1772181231"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1772168325"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772167317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1772157328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772166890"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772167008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772150798"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772150820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772149345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772149330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772150705"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772150844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772150771"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772150828"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772149306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1772150731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1772150759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772758175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1772151055"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1772167480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1772169582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1772168208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772167234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772167740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1772168967"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-rhel9:1772167409"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1772168373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772167462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772168176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772167544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772167861"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772167359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772167787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772167838"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772166959"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772167749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772168066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772166968"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772168113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772167859"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772167681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772167936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772157422"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772167226"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772181032"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1772167384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772595132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772168149"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772181009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1772709768"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772181022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1773215644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1772168183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772166718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772168076"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772181016"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772167789"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772477555"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772181012"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772167303"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9:1773096874"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772168220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1772168465"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-coredns-rhel9:1772181028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772154330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1772154031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772758170"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772167160"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1772166820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1772168206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772165961"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1772167933"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1772168079"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772181009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1772732473"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772167583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-etcd-rhel9:1772168302"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772154896"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772155817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1772154368"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772155114"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1772166752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772167456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hypershift-rhel9:1773125843"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772166192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772167204"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772166058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772758129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1772166233"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1772758160"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772165687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1772168742"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-rhel9:1772181272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1773057061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772181213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1772157180"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772167648"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772166097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772165479"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772165468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772151123"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772150802"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772155068"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772686568"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772166247"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1773184042"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1772709791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772165550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1772168198"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1772168446"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772686595"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1772166453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1772157220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-must-gather-rhel9:1772168903"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1772166450"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772165931"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772149183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772150968"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772166205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772167976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772167261"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1772165817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1772166052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772165925"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772166357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772166715"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772165985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1772165440"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772165924"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1772167832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1772595791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1772595334"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1772157323"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1772595900"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1773184641"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1773184785"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-pod-rhel9:1772168337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772758222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1772155094"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772154869"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772153399"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1772168339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772595658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1772168168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772595499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9:1772167208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772595786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1772166706"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772157057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772157116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tests-rhel9:1773220566"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-thanos-rhel9:1772157258"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tools-rhel9:1773215681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772758087"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1772150646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772686584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772150699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1772758087"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1772150646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772150660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772150954"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772166356"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772167335"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4435",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-container-rhel9:1772758627"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4435",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-rhel9-operator:1773215173"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4435",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-clusterresourceoverride-rhel9:1772166797"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4435",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-clusterresourceoverride-rhel9-operator:1772168180"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4435",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-filestore-csi-driver-rhel9:1772758223"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4435",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-local-storage-diskmaker-rhel9:1772157194"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4435",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-local-storage-mustgather-rhel9:1772169772"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4435",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-local-storage-rhel9-operator:1772157119"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4435",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9:1772166215"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4435",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9-operator:1772166323"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4435",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vertical-pod-autoscaler-rhel9:1772168027"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4435",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vertical-pod-autoscaler-rhel9-operator:1772181014"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1775572657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1775563654"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17468",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1778138510"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17468",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1778138146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17468",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1778138158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1772143108"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1772144253"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1772143861"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/azure-service-rhel9-operator:1772141804"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1772142576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1772144019"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/egress-router-cni-rhel9:1772143220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/frr-rhel9:1772143999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1772644085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1772644229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1772144695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1772141175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/network-tools-rhel9:1772595158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772574958"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1772144029"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/openstack-resource-controller-rhel9:1772143448"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1772523439"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1772523362"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772144004"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1772142177"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-ui-rhel9:1772138687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772142349"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772141184"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772138481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772138558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772138512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772138499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772138530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772138511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772138620"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772138530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772138605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1772138480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1772138526"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772138550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1772138504"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1772144786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1772655529"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1772144359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772143306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772142354"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1772524224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cli-rhel9:1772523269"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1772144014"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772142857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772144745"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772141413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772143467"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772574867"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772141541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772144616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772143505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772142729"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772144375"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772143219"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772141833"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772142083"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772141487"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772144675"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772141562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772144499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772144468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1772142357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772574880"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772143585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772142637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1772523242"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772142186"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1772593591"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1772143567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772143784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772143458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772141103"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772144434"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772141786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772143296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772142921"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-console-rhel9:1772142269"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772141663"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1772142278"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-coredns-rhel9:1772142665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772139730"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1772140894"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772141273"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772144699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1772142097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1772144027"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-snapshot-metadata-rhel9:1772144260"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772144056"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1772142266"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1772142511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772144436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1772143090"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772142447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-etcd-rhel9:1772143126"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772142217"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772141921"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1772140710"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772666832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1772143233"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772141417"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-hypershift-rhel9:1772574935"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772143941"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772138681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772138704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772139730"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1772144828"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1772490783"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772141241"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1772655389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-installer-rhel9:1772655272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1772593911"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772143650"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1772141436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772141284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772142819"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772142058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772141707"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772138490"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772138544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772142856"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772141988"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772143281"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1772608175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1772644163"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772143907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1772144363"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1772144275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772644153"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1772143637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1772144106"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-must-gather-rhel9:1772524101"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1772143661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772144523"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772138417"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772138382"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772141254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772144025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772574868"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1772144410"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1772142572"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772144691"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772142646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772141699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772666702"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1772143222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772141559"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1772143082"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1772176727"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1772176665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1772143531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1772176674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1772467275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1772523424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-pod-rhel9:1772143045"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772140895"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1772142175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772141519"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772143131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1772143435"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772433633"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1772144466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772433634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-rhel9:1772143543"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772433630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1772142820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772142573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772141358"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-tests-rhel9:1772655350"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-thanos-rhel9:1772141288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-tools-rhel9:1772593622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772138438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1772138413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772138401"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772138414"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772138437"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772138403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772141084"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772141210"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/volume-data-source-validator-rhel9:1772141838"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3856",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-container-rhel9:1772138471"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3856",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-rhel9-operator:1772593538"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3856",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-clusterresourceoverride-rhel9:1772144394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3856",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-clusterresourceoverride-rhel9-operator:1772142511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3856",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-filestore-csi-driver-rhel9:1772142778"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3856",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-local-storage-diskmaker-rhel9:1772142226"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3856",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-local-storage-mustgather-rhel9:1772524722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3856",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-local-storage-rhel9-operator:1772523227"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3856",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9:1772144773"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3856",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9-operator:1772142552"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3856",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vertical-pod-autoscaler-rhel9:1772141550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3856",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vertical-pod-autoscaler-rhel9-operator:1772142304"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1775054956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8431",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-dpu-daemon-rhel9:1776231768"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8431",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-dpu-rhel9-operator:1776231668"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9:1781555717"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9-operator:1781554936"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-core-rhel9:1781555645"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-rhel9-operator:1781556009"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-console-rhel9:1781558423"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-rhel9-operator:1781555708"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1781557202"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-rhel9-operator:1781555679"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cli-rhel9:1781557189"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-console-rhel9:1781556534"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1781556085"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1781555971"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1781557158"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1781556690"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1781558326"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-must-gather-rhel9:1781556544"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-rhel9-operator:1781556958"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odr-rhel9-operator:1781556901"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26420",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1781557496"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9:1783676191"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9-operator:1783929816"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-core-rhel9:1784094353"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-rhel9-operator:1784093953"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-console-rhel9:1784094943"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-rhel9-operator:1783676585"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1783676649"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-rhel9-operator:1783676675"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cli-rhel9:1784094299"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-console-rhel9:1784094725"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1783676820"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1783676883"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1783676894"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1784095175"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1783676977"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-must-gather-rhel9:1784093503"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-rhel9-operator:1783677297"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odr-rhel9-operator:1783677345"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1783677533"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9:1786705347"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9-operator:1786706101"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-core-rhel9:1786705558"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-rhel9-operator:1786705646"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-console-rhel9:1786706138"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-rhel9-operator:1786705741"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1786705777"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-rhel9-operator:1786705802"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cli-rhel9:1786705938"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-console-rhel9:1786706577"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1786706125"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1786706177"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1786706188"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1786706679"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1786706357"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-must-gather-rhel9:1786706612"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-rhel9-operator:1786706644"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odr-rhel9-operator:1786706659"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1786706880"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9:1776079019"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9-operator:1776706744"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-core-rhel9:1776707205"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-rhel9-operator:1776707231"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-console-rhel9:1776707760"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-rhel9-operator:1776707301"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1776079295"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-rhel9-operator:1776707362"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cli-rhel9:1776707418"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1776707377"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-console-rhel9:1776707947"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1776707456"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1776707526"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1776707526"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1776707945"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1776707569"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-must-gather-rhel9:1776707724"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-rhel9-operator:1776707763"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odr-rhel9-operator:1776707771"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1776079774"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9:1786701839"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9-operator:1786701555"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-core-rhel9:1786702052"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-rhel9-operator:1786702559"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-console-rhel9:1786702713"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-rhel9-operator:1786702264"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1786702448"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-rhel9-operator:1786702276"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cli-rhel9:1786702440"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1786702315"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-console-rhel9:1786703071"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1786702563"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1786702636"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1786702623"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1786703137"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1786702716"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-must-gather-rhel9:1786702872"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-rhel9-operator:1786702949"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odr-rhel9-operator:1786702917"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1786703143"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9:1774379712"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9-operator:1774379710"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-core-rhel9:1774379660"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-rhel9-operator:1774379768"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-console-rhel9:1774432831"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-rhel9-operator:1774379856"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1774379911"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-rhel9-operator:1774379915"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cli-rhel9:1774379986"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1774379972"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-console-rhel9:1774380550"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1774380042"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1774380111"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1774380106"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1774380582"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1774380190"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-must-gather-rhel9:1774380303"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-rhel9-operator:1774380423"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odr-rhel9-operator:1774380409"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6184",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1774380526"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/cephcsi-rhel9:1786627460"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/cephcsi-rhel9-operator:1786626399"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/mcg-core-rhel9:1786628235"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/mcg-rhel9-operator:1786627106"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-client-console-rhel9:1786629761"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-client-rhel9-operator:1786627559"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1786687918"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-rhel9-operator:1786629478"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cli-rhel9:1786628142"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1786631508"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-console-rhel9:1786628053"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1786627382"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1786627430"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1786629076"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-external-snapshotter-rhel9-operator:1786627469"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-external-snapshotter-sidecar-rhel9:1786644072"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1786688215"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1786628340"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-must-gather-rhel9:1786628623"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-rhel9-operator:1786632256"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odr-rhel9-operator:1786628935"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1786629548"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.27",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6192",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.27::el9",
        "package": "devspaces/code-rhel9:1774448966"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.27",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6192",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.27::el9",
        "package": "devspaces/configbump-rhel9:1774155063"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.27",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6192",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.27::el9",
        "package": "devspaces/devspaces-rhel9-operator:1774607447"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.27",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6192",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.27::el9",
        "package": "devspaces/imagepuller-rhel9:1774587761"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.27",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6192",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.27::el9",
        "package": "devspaces/traefik-rhel9:1774227265"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.27",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6192",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.27::el9",
        "package": "devspaces/udi-base-rhel10:1774143680"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.27",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6192",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.27::el9",
        "package": "devspaces/udi-base-rhel9:1774070844"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.27",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6192",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.27::el9",
        "package": "devspaces/udi-rhel9:1774451954"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces (RHOSDS) 3.26",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2844",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.26::el9",
        "package": "devspaces/udi-rhel9:1770913862"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3427",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/opentelemetry-collector-rhel9:1771517504"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3427",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/opentelemetry-rhel9-operator:1771517356"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3427",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/opentelemetry-target-allocator-rhel9:1771517323"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3459",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/tempo-gateway-opa-rhel9:1771843135"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3459",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/tempo-gateway-rhel9:1771843440"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3459",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/tempo-jaeger-query-rhel9:1771843277"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3459",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/tempo-operator-bundle:1771847684"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3459",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/tempo-query-rhel9:1771843085"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3459",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/tempo-rhel9-operator:1771843096"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.17",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3869",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.17::el8",
        "package": "openshift-gitops-1/argocd-agent-rhel8:1772195985"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.17",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3869",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.17::el8",
        "package": "openshift-gitops-1/argocd-rhel8:1772196046"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.17",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3869",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.17::el8",
        "package": "openshift-gitops-1/argocd-rhel9:1772196361"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.17",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3869",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.17::el8",
        "package": "openshift-gitops-1/argo-rollouts-rhel8:1772195911"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.17",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3869",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.17::el8",
        "package": "openshift-gitops-1/dex-rhel8:1772196395"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.17",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3869",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.17::el8",
        "package": "openshift-gitops-1/gitops-rhel8:1772196395"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.17",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3869",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.17::el8",
        "package": "openshift-gitops-1/gitops-rhel8-operator:1772196638"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.18",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3874",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.18::el8",
        "package": "openshift-gitops-1/argocd-agent-rhel8:1772438619"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.18",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3874",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.18::el8",
        "package": "openshift-gitops-1/argocd-rhel8:1772439857"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.18",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3874",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.18::el8",
        "package": "openshift-gitops-1/argocd-rhel9:1772439154"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.18",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3874",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.18::el8",
        "package": "openshift-gitops-1/argo-rollouts-rhel8:1772439531"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.18",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3874",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.18::el8",
        "package": "openshift-gitops-1/dex-rhel8:1772438555"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.18",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3874",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.18::el8",
        "package": "openshift-gitops-1/gitops-rhel8:1772439275"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.18",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3874",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.18::el8",
        "package": "openshift-gitops-1/gitops-rhel8-operator:1772438494"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.19",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3884",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.19::el8",
        "package": "openshift-gitops-1/argocd-agent-rhel8:1772444686"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.19",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3884",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.19::el8",
        "package": "openshift-gitops-1/argocd-image-updater-rhel8:1772444855"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.19",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3884",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.19::el8",
        "package": "openshift-gitops-1/argocd-rhel8:1772444491"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.19",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3884",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.19::el8",
        "package": "openshift-gitops-1/argocd-rhel9:1772448378"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.19",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3884",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.19::el8",
        "package": "openshift-gitops-1/argo-rollouts-rhel8:1772446597"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.19",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3884",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.19::el8",
        "package": "openshift-gitops-1/dex-rhel8:1772445569"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.19",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3884",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.19::el8",
        "package": "openshift-gitops-1/gitops-rhel8:1772446341"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/istio-cni-rhel8:1771992208"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/istio-rhel8-operator:1771992461"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/pilot-rhel8:1771992212"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/ratelimit-rhel8:1771992437"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5132",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/kiali-rhel8:1773059917"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8483",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/kiali-rhel8:1776191302"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3556",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el9",
        "package": "openshift-service-mesh/proxyv2-rhel9:1772083861"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5129",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/kiali-rhel9:1773059790"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1774214116"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1774006090"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1774068855"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1774294372"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5131",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/kiali-rhel9:1773060321"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1774037349"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1774037369"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1774244136"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1774293851"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5130",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/kiali-rhel9:1773060306"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1774206585"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1774206464"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1774114903"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1774294809"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5394",
        "cpe": "cpe:/a:redhat:openstack:17.1::el9",
        "package": "rhosp-rhel9/osp-director-agent:1773255177"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5394",
        "cpe": "cpe:/a:redhat:openstack:17.1::el9",
        "package": "rhosp-rhel9/osp-director-operator:1773255175"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/barbican-rhel9-operator:1774976894"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/cinder-rhel9-operator:1774976892"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/designate-rhel9-operator:1774974095"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/glance-rhel9-operator:1774976891"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/heat-rhel9-operator:1774976892"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/horizon-rhel9-operator:1774976890"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/infra-rhel9-operator:1774973634"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/ironic-rhel9-operator:1774976892"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/keystone-rhel9-operator:1774973242"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/manila-rhel9-operator:1774976894"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/mariadb-rhel9-operator:1774976903"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/mysqld-exporter-rhel9:1774973256"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/neutron-rhel9-operator:1774976893"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/nova-rhel9-operator:1774973309"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/octavia-rhel9-operator:1774974137"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/openstack-baremetal-agent-rhel9:1774537171"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/openstack-baremetal-rhel9-operator:1774974056"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/openstack-network-exporter-rhel9:1774974413"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/openstack-rhel9-operator:1776882788"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/ovn-rhel9-operator:1774976892"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/placement-rhel9-operator:1774974045"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/prometheus-podman-exporter-rhel9:1774974078"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/rabbitmq-cluster-rhel9-operator:1774974449"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/sg-core-rhel9:1774974026"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/swift-rhel9-operator:1774976892"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/telemetry-rhel9-operator:1774973876"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/test-rhel9-operator:1774974317"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/watcher-rhel9-operator:1774973636"
      },
      {
        "product_name": "Red Hat Quay 3.1",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5665",
        "cpe": "cpe:/a:redhat:quay:3.10::el8",
        "package": "quay/quay-rhel8:1773971077"
      },
      {
        "product_name": "Red Hat Quay 3.12",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4942",
        "cpe": "cpe:/a:redhat:quay:3.12::el8",
        "package": "quay/quay-rhel8:1773771962"
      },
      {
        "product_name": "Red Hat Quay 3.14",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:21017",
        "cpe": "cpe:/a:redhat:quay:3.14::el8",
        "package": "quay/quay-rhel8:1779689392"
      },
      {
        "product_name": "Red Hat Quay 3.15",
        "release_date": "2026-04-03T00:00:00Z",
        "advisory": "RHSA-2026:6568",
        "cpe": "cpe:/a:redhat:quay:3.15::el8",
        "package": "quay/quay-rhel8:1775169219"
      },
      {
        "product_name": "Red Hat Quay 3.16",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19375",
        "cpe": "cpe:/a:redhat:quay:3.16::el9",
        "package": "quay/quay-rhel9:1779204086"
      },
      {
        "product_name": "Red Hat Quay 3.16",
        "release_date": "2026-02-12T00:00:00Z",
        "advisory": "RHSA-2026:2681",
        "cpe": "cpe:/a:redhat:quay:3.16::el9",
        "package": "quay/quay-rhel9:1770836901"
      },
      {
        "product_name": "Red Hat Quay 3.16",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6497",
        "cpe": "cpe:/a:redhat:quay:3.16::el9",
        "package": "quay/quay-rhel9:1775069491"
      },
      {
        "product_name": "Red Hat Quay 3.16",
        "release_date": "2026-04-03T00:00:00Z",
        "advisory": "RHSA-2026:6567",
        "cpe": "cpe:/a:redhat:quay:3.16::el9",
        "package": "quay/quay-rhel9:1775169226"
      },
      {
        "product_name": "Red Hat Quay 3.9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23361",
        "cpe": "cpe:/a:redhat:quay:3.9::el8",
        "package": "quay/quay-rhel8:1779811473"
      },
      {
        "product_name": "Red Hat Quay 3.9",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2754",
        "cpe": "cpe:/a:redhat:quay:3.9::el8",
        "package": "quay/quay-rhel8:1770856103"
      },
      {
        "product_name": "Red Hat Quay 3.9",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5168",
        "cpe": "cpe:/a:redhat:quay:3.9::el8",
        "package": "quay/quay-rhel8:1773936323"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14879",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/iop-vmaas-rhel9:1778082595"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15984",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/iop-ingress-rhel9:1777999365"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3184",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/policy-controller-rhel9:1771517629"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3296",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/policy-controller-rhel9-operator:1771931708"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:4276",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/model-validation-rhel9-operator:1772622245"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5439",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/createtree-rhel9:1773231678"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5444",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/rekor-monitor-rhel9:1773238681"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5447",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/certificate-transparency-rhel9:1773308392"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5447",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/fulcio-rhel9:1773307677"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5447",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/rekor-backfill-redis-rhel9:1773307592"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5447",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/rekor-server-rhel9:1773307592"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5447",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/timestamp-authority-rhel9:1773307765"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5447",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/trillian-database-rhel9:1773307620"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5447",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/trillian-logserver-rhel9:1773231678"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5447",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/trillian-logsigner-rhel9:1773231678"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5452",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/cosign-rhel9:1773309219"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5452",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/gitsign-rhel9:1773307743"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5452",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/rekor-cli-rhel9:1773307592"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5452",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/updatetree-rhel9:1773231678"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5463",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/rhtas-rhel9-operator:1773318584"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5649",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/rhtas-console-rhel9:1774254230"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1773670137"
      },
      {
        "product_name": "Red Hat Web Terminal 1.11",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10250",
        "cpe": "cpe:/a:redhat:webterminal:1.11::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1776966691"
      },
      {
        "product_name": "Red Hat Web Terminal 1.11",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10250",
        "cpe": "cpe:/a:redhat:webterminal:1.11::el9",
        "package": "web-terminal/web-terminal-rhel9-operator:1776966690"
      },
      {
        "product_name": "Red Hat Web Terminal 1.12",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10225",
        "cpe": "cpe:/a:redhat:webterminal:1.12::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1776959849"
      },
      {
        "product_name": "Red Hat Web Terminal 1.12",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10225",
        "cpe": "cpe:/a:redhat:webterminal:1.12::el9",
        "package": "web-terminal/web-terminal-rhel9-operator:1776959828"
      },
      {
        "product_name": "Red Hat Web Terminal 1.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8338",
        "cpe": "cpe:/a:redhat:webterminal:1.13::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1776197785"
      },
      {
        "product_name": "Red Hat Web Terminal 1.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8338",
        "cpe": "cpe:/a:redhat:webterminal:1.13::el9",
        "package": "web-terminal/web-terminal-rhel9-operator:1776197691"
      },
      {
        "product_name": "Red Hat Web Terminal 1.14",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8337",
        "cpe": "cpe:/a:redhat:webterminal:1.14::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1776199398"
      },
      {
        "product_name": "Red Hat Web Terminal 1.14",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8337",
        "cpe": "cpe:/a:redhat:webterminal:1.14::el9",
        "package": "web-terminal/web-terminal-rhel9-operator:1776199421"
      },
      {
        "product_name": "Red Hat Web Terminal 1.15",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8167",
        "cpe": "cpe:/a:redhat:webterminal:1.15::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1775672762"
      },
      {
        "product_name": "Red Hat Web Terminal 1.15",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8167",
        "cpe": "cpe:/a:redhat:webterminal:1.15::el9",
        "package": "web-terminal/web-terminal-rhel9-operator:1775672765"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager 1.0",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17460",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1.0::el9",
        "package": "zero-trust-workload-identity-manager/spiffe-spire-controller-manager-rhel9:1778248669"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager 1.0",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17463",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1.0::el9",
        "package": "zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9:1778250211"
      }
    ],
    "package_state": [
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "rhai/assisted-installer-agent-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "rhai/assisted-installer-controller-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "rhai/assisted-installer-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/cert-manager-istio-csr-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "build-of-trustee/trustee-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "openshift-sandboxed-containers/osc-cloud-api-adaptor-webhook-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "openshift-sandboxed-containers/osc-monitor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Cryostat 4",
        "fix_state": "Affected",
        "package_name": "cryostat/cryostat-grafana-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:cryostat:4"
      },
      {
        "product_name": "Cryostat 4",
        "fix_state": "Will not fix",
        "package_name": "cryostat/cryostat-ose-oauth-proxy-rhel9",
        "cpe": "cpe:/a:redhat:cryostat:4"
      },
      {
        "product_name": "Cryostat 4",
        "fix_state": "Affected",
        "package_name": "cryostat/cryostat-rhel9-operator",
        "cpe": "cpe:/a:redhat:cryostat:4"
      },
      {
        "product_name": "Custom Metric Autoscaler operator for Red Hat Openshift",
        "fix_state": "Affected",
        "package_name": "custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
      },
      {
        "product_name": "Custom Metric Autoscaler operator for Red Hat Openshift",
        "fix_state": "Affected",
        "package_name": "custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
      },
      {
        "product_name": "Deployment Validation Operator",
        "fix_state": "Affected",
        "package_name": "dvo/deployment-validation-rhel8-operator",
        "cpe": "cpe:/a:redhat:deployment_validator_operator"
      },
      {
        "product_name": "ExternalDNS Operator",
        "fix_state": "Affected",
        "package_name": "edo/external-dns-rhel8",
        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
      },
      {
        "product_name": "ExternalDNS Operator",
        "fix_state": "Affected",
        "package_name": "edo/external-dns-rhel8-operator",
        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
      },
      {
        "product_name": "ExternalDNS Operator",
        "fix_state": "Not affected",
        "package_name": "edo/external-dns-rhel9",
        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
      },
      {
        "product_name": "ExternalDNS Operator",
        "fix_state": "Not affected",
        "package_name": "edo/external-dns-rhel9-operator",
        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
      },
      {
        "product_name": "Fence Agents Remediation Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/fence-agents-remediation-operator-bundle",
        "cpe": "cpe:/a:redhat:workload_availability_far:0"
      },
      {
        "product_name": "Fence Agents Remediation Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/fence-agents-remediation-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_far:0"
      },
      {
        "product_name": "File Integrity Operator",
        "fix_state": "Affected",
        "package_name": "compliance/openshift-compliance-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1"
      },
      {
        "product_name": "File Integrity Operator",
        "fix_state": "Affected",
        "package_name": "compliance/openshift-file-integrity-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1"
      },
      {
        "product_name": "Gatekeeper 3",
        "fix_state": "Will not fix",
        "package_name": "gatekeeper/gatekeeper-rhel9-operator",
        "cpe": "cpe:/a:redhat:gatekeeper:3"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/elasticsearch-proxy-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/elasticsearch-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/loki-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/lokistack-gateway-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/opa-openshift-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Not affected",
        "package_name": "lvms4/lvms-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Affected",
        "package_name": "lvms4/lvms-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Affected",
        "package_name": "lvms4/lvms-operator-bundle",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Affected",
        "package_name": "lvms4/lvms-rhel9-operator",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Not affected",
        "package_name": "lvms4/topolvm-rhel8",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Affected",
        "package_name": "lvms4/topolvm-rhel9",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/machine-deletion-remediation-operator-bundle",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/machine-deletion-remediation-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-analyzer-addon-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-cli-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-discovery-addon-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-dotnet-external-provider-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-dotnet-external-provider-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-generic-external-provider-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-hub-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-java-external-provider-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-platform-addon-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-solution-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "mirror registry for Red Hat OpenShift",
        "fix_state": "Will not fix",
        "package_name": "openshift/mirror-registry-rhel8",
        "cpe": "cpe:/a:redhat:mirror_registry:1"
      },
      {
        "product_name": "Multiarch Tuning Operator",
        "fix_state": "Affected",
        "package_name": "multiarch-tuning/multiarch-tuning-rhel9-operator",
        "cpe": "cpe:/a:redhat:multiarch_tuning_operator"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-image-service-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-image-service-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-agent-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-agent-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-controller-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-controller-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-service-8-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-service-9-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/cluster-api-provider-agent-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/cluster-api-provider-aws-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/cluster-api-provider-kubevirt-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/hypershift-addon-rhel9-operator",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/image-based-install-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/kube-rbac-proxy-mce-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/mce-capi-webhook-config-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/node-healthcheck-operator-bundle",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Will not fix",
        "package_name": "workload-availability/node-healthcheck-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "Node Maintenance Operator",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/node-maintenance-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nmo:5"
      },
      {
        "product_name": "Node Maintenance Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/node-maintenance-operator-bundle",
        "cpe": "cpe:/a:redhat:workload_availability_nmo:5"
      },
      {
        "product_name": "Node Maintenance Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/node-maintenance-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nmo:5"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "helm",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-jenkins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/openshift-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines-client",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "kn-workflow-plugin",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Will not fix",
        "package_name": "openshift-serverless-1/kn-plugin-event-sender-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Will not fix",
        "package_name": "openshift-serverless-1/kn-plugin-func-func-util-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Will not fix",
        "package_name": "openshift-serverless-clients",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Power monitoring for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-power-monitoring/kepler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_power_monitoring"
      },
      {
        "product_name": "Power monitoring for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-power-monitoring/power-monitoring-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_power_monitoring"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Affected",
        "package_name": "3scale-amp2/3scale-apicast-operator-bundle",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Affected",
        "package_name": "3scale-amp2/3scale-operator-bundle",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp2/3scale-rhel7-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Affected",
        "package_name": "3scale-amp2/3scale-rhel9-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp26/3scale-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp26/operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp2/apicast-rhel7-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Affected",
        "package_name": "3scale-amp2/apicast-rhel9-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-tech-preview/authorino-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Affected",
        "package_name": "rhcl-1/authorino-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-kube-rbac-proxy",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-kube-state-metrics",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-kube-state-metrics-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-grafana-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-multicluster-observability-addon-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-prometheus-config-reloader-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-prometheus-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-search-indexer-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-search-v2-api-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-search-v2-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-siteconfig-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/endpoint-monitoring-rhel9-operator",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/grafana-dashboard-loader-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/insights-client-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/insights-metrics-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/klusterlet-addon-controller-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/kube-rbac-proxy-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/kube-state-metrics-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/memcached-exporter-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/metrics-collector-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/mtv-integrations-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multicluster-observability-rhel9-operator",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/node-exporter-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/observatorium-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/observatorium-rhel9-operator",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/prometheus-alertmanager-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/prometheus-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/rbac-query-proxy-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/search-collector-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/submariner-addon-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/thanos-receive-controller-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/thanos-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/volsync-operator-bundle",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat AMQ Clients",
        "fix_state": "Will not fix",
        "package_name": "python39-qpid-proton",
        "cpe": "cpe:/a:redhat:amq_clients:2023"
      },
      {
        "product_name": "Red Hat AMQ Clients",
        "fix_state": "Will not fix",
        "package_name": "python3-qpid-proton",
        "cpe": "cpe:/a:redhat:amq_clients:2023"
      },
      {
        "product_name": "Red Hat AMQ Clients",
        "fix_state": "Will not fix",
        "package_name": "qpid-proton",
        "cpe": "cpe:/a:redhat:amq_clients:2023"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform/platform-operator-bundle",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-on-clouds/aoc-azure-aap-installer-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "automation-gateway-proxy-openssl30",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "automation-gateway-proxy-openssl32",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "python3.11-galaxy-ng",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3.11-grpcio",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3x-grpcio",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python-grpcio",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/snmp-notifier-rhel8",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/snmp-notifier-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Fix deferred",
        "package_name": "rhel8/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Fix deferred",
        "package_name": "ceph",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/snmp-notifier-rhel8",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/snmp-notifier-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Fix deferred",
        "package_name": "rhel8/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Fix deferred",
        "package_name": "ceph",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/snmp-notifier-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Fix deferred",
        "package_name": "ceph",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/snmp-notifier-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Certification Program for Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "redhat-certification-preflight",
        "cpe": "cpe:/a:redhat:certifications:9"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Affected",
        "package_name": "rhcl-1/authorino-operator-bundle",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Affected",
        "package_name": "rhcl-1/authorino-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Affected",
        "package_name": "rhcl-1/authorino-rhel9-operator",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Affected",
        "package_name": "rhcl-1/coredns-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Affected",
        "package_name": "rhcl-1/dns-rhel9-operator",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Affected",
        "package_name": "rhcl-1/limitador-rhel9-operator",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Will not fix",
        "package_name": "rhcl-1/rhcl-operator-bundle",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Affected",
        "package_name": "rhcl-1/rhcl-rhel9-operator",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Affected",
        "package_name": "flightctl",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Affected",
        "package_name": "rhem/flightctl-alert-exporter-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Affected",
        "package_name": "rhem/flightctl-alertmanager-proxy-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Affected",
        "package_name": "rhem/flightctl-api-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Affected",
        "package_name": "rhem/flightctl-cli-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Affected",
        "package_name": "rhem/flightctl-db-setup-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Affected",
        "package_name": "rhem/flightctl-pam-issuer-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Affected",
        "package_name": "rhem/flightctl-periodic-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Affected",
        "package_name": "rhem/flightctl-telemetry-gateway-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Affected",
        "package_name": "rhem/flightctl-ui-ocp-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Affected",
        "package_name": "rhem/flightctl-ui-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Affected",
        "package_name": "rhem/flightctl-userinfo-proxy-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Affected",
        "package_name": "rhem/flightctl-worker-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "butane",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "gvisor-tap-vsock",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "ignition",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "rhel10/bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "rhel10-eus/rhel-10.0-bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rsyslog",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "host-metering",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "rhc-worker-script",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "rsyslog",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "weldr-client",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "butane",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "go-toolset",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "gvisor-tap-vsock",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "ignition",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "rhel9/bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "rhel9-eus/rhel-9.6-bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rsyslog",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "weldr-client",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-argoexec-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-data-science-pipelines-operator-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-feast-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kuberay-operator-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kueue-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kueue-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-maas-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-launcher-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mm-rest-proxy-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-gen-ai-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-modelmesh-serving-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-metadata-collection-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-registry-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-training-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-training-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-trustyai-service-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Cluster Manager CLI",
        "fix_state": "Affected",
        "package_name": "ocm-cli-clients/ocm-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_cluster_manager_cli:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "butane",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "ignition",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "microshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/frr-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ingress-node-firewall",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ingress-node-firewall-daemon-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ingress-node-firewall-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/kube-compare-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/kubernetes-nmstate-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/lifecycle-agent-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/lifecycle-agent-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/metallb-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/metallb-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/metallb-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-aws-ebs-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-aws-efs-csi-driver-container-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-aws-efs-csi-driver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-clusterresourceoverride-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-clusterresourceoverride-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-external-attacher",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-external-attacher-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-external-provisioner",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-external-provisioner-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-external-resizer",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-external-resizer-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-external-snapshotter",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-external-snapshotter-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-livenessprobe",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-livenessprobe-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-node-driver-registrar",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-node-driver-registrar-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-snapshot-controller",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-snapshot-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-snapshot-validation-webhook-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-dpu-cni-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-dpu-daemon-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-dpu-intel-ipu-p4sdk-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-dpu-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-gcp-filestore-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-helm-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-helm-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ibmcloud-machine-controllers-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-kubernetes-nmstate-handler-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-local-storage-diskmaker-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-local-storage-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-local-storage-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-nutanix-machine-controllers-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-sdk-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-powervs-block-csi-driver-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-powervs-block-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-powervs-cloud-controller-manager-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-powervs-machine-controllers-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-secrets-store-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-secrets-store-csi-driver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-secrets-store-csi-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-smb-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-smb-csi-driver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-sriov-dp-admission-controller",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-sriov-infiniband-cni",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-sriov-network-config-daemon",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-sriov-network-device-plugin",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-sriov-network-metrics-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-sriov-network-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-sriov-network-webhook",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-support-log-gather-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vertical-pod-autoscaler-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vertical-pod-autoscaler-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/pf-status-relay-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/sriov-cni-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/sriov-network-metrics-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/topology-aware-lifecycle-manager-aztp-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/topology-aware-lifecycle-manager-recovery-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/topology-aware-lifecycle-manager-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift-tech-preview/metallb-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/machineexec-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Affected",
        "package_name": "rhosdt/opentelemetry-collector-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Affected",
        "package_name": "rhosdt/opentelemetry-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Affected",
        "package_name": "rhosdt/opentelemetry-target-allocator-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Affected",
        "package_name": "rhosdt/tempo-gateway-opa-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Affected",
        "package_name": "rhosdt/tempo-gateway-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Affected",
        "package_name": "rhosdt/tempo-jaeger-query-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Affected",
        "package_name": "rhosdt/tempo-query-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Affected",
        "package_name": "rhosdt/tempo-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Will not fix",
        "package_name": "openshift4-wincw/windows-machine-config-operator-bundle",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Will not fix",
        "package_name": "openshift4-wincw/windows-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift on AWS",
        "fix_state": "Affected",
        "package_name": "rosa",
        "cpe": "cpe:/a:redhat:openshift_service_on_aws:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/aaq-controller-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/aaq-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/aaq-server-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/bridge-marker-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/cluster-network-addons-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/cnv-containernetworking-plugins-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/hostpath-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/hostpath-provisioner-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/hostpath-provisioner-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/hyperconverged-cluster-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/hyperconverged-cluster-webhook-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/kubemacpool-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/kubesecondarydns-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/kubevirt-api-lifecycle-automation-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/kubevirt-apiserver-proxy-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/kubevirt-ipam-controller-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/kubevirt-ssp-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/kubevirt-storage-checkup-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/kubevirt-tekton-tasks-create-datavolume-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/kubevirt-template-validator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/multus-dynamic-networks-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/ocp-virt-validation-checkup-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/ovs-cni-plugin-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/passt-network-binding-plugin-cni-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/passt-network-binding-plugin-sidecar-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/sidecar-shim-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-api",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-api-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-artifacts-server-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-cdi-apiserver-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-cdi-cloner-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-cdi-controller-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-cdi-importer-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-cdi-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-cdi-uploadproxy-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-cdi-uploadserver-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-controller-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-exportproxy-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-exportserver-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-handler-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-launcher-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-migration-controller-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-migration-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-synchronization-controller-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/vm-console-proxy-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/vm-network-latency-checkup-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/wasp-agent-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "hyperconverged-cluster-operator-test-rhel9-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "kubevirt",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "kubevirt-ssp-operator-test-rhel9-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "kubevirt-tekton-tasks-test-rhel9-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "redfish-event-listener-rhel9-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "virt-template-apiserver-rhel9-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "virt-template-controller-rhel9-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "virt-template-test-rhel9-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "golang-github-infrawatch-apputils",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "golang-qpid-apache",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "qpid-proton",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/osp-director-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/osp-director-operator",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/osp-director-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Affected",
        "package_name": "collectd-libpod-stats",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Affected",
        "package_name": "golang-github-infrawatch-apputils",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Affected",
        "package_name": "golang-qpid-apache",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "qpid-proton",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel9/osp-director-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/openstack-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/clair-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/clair-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-bridge-operator-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-bridge-operator-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-builder-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-builder-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-container-security-operator-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-container-security-operator-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-operator-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "satellite:el8/yggdrasil-worker-forwarder",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Service Interconnect 1",
        "fix_state": "Will not fix",
        "package_name": "qpid-proton",
        "cpe": "cpe:/a:redhat:service_interconnect:1"
      },
      {
        "product_name": "Red Hat Service Interconnect 1",
        "fix_state": "Not affected",
        "package_name": "skupper-cli",
        "cpe": "cpe:/a:redhat:service_interconnect:1"
      },
      {
        "product_name": "Red Hat Service Interconnect 2",
        "fix_state": "Will not fix",
        "package_name": "qpid-proton",
        "cpe": "cpe:/a:redhat:service_interconnect:2"
      },
      {
        "product_name": "Red Hat Service Interconnect 2",
        "fix_state": "Not affected",
        "package_name": "skupper-cli",
        "cpe": "cpe:/a:redhat:service_interconnect:2"
      },
      {
        "product_name": "Red Hat Service Interconnect 2",
        "fix_state": "Will not fix",
        "package_name": "skupper-router",
        "cpe": "cpe:/a:redhat:service_interconnect:2"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-server-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-server-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-61726\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-61726\nhttps://go.dev/cl/736712\nhttps://go.dev/issue/77101\nhttps://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc\nhttps://pkg.go.dev/vuln/GO-2026-4341"
    ],
    "name": "CVE-2025-61726",
    "mitigation": {
      "value": "Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-01-28T19:30:30Z",
    "bugzilla": {
      "description": "cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive",
      "id": "2434433",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2434433"
    },
    "cvss3": {
      "cvss3_base_score": "8.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-88",
    "details": [
      "Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The \"#cgo pkg-config:\" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a \"--log-file\" argument to this directive, causing pkg-config to write to an attacker-controlled location.",
      "A flaw was found in cmd/go. An attacker can exploit this by building a malicious Go source file that uses the '#cgo pkg-config:' directive. This allows the attacker to write to an arbitrary file with partial control over its content, by providing a '--log-file' argument to the pkg-config command. This vulnerability can lead to arbitrary file write."
    ],
    "statement": "This vulnerability is Important rather than Moderate because compiling a malicious Go source file can cause `pkg-config` to create or append data to files at attacker-chosen locations, subject to the permissions of the build user. This can enable unintended filesystem modifications during the build process, which can lead to broken builds, alter tool behavior, and poison caches or artifacts, even without direct code execution.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5941",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "golang-0:1.25.8-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5943",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "golang-0:1.25.8-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:6949",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "go-toolset:rhel8-8100020260402232122.a3795dee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7878",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "go-toolset:rhel8-8020020260408140623.02f7cb7a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7879",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "go-toolset:rhel8-8040020260408080443.5081a262"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7879",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "go-toolset:rhel8-8040020260408080443.5081a262"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7876",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "go-toolset:rhel8-8060020260409063558.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7876",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "go-toolset:rhel8-8060020260409063558.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7876",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "go-toolset:rhel8-8060020260409063558.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7877",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "go-toolset:rhel8-8080020260331223648.6b4b45d8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7877",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "go-toolset:rhel8-8080020260331223648.6b4b45d8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5942",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "golang-0:1.25.8-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7883",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "golang-0:1.17.13-11.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7833",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "golang-0:1.19.13-24.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7834",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "golang-0:1.21.13-15.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5944",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "golang-0:1.25.8-1.el9_6"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7291",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-26-main-1.26.2-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7385",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-25-main-1.25.9-1.hum1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1777002694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/egress-router-cni-rhel8:1777001625"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1777001562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/network-tools-rhel8:1777002936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1777042122"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1777001567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1777002279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1777002206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel8:1777001821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1777002716"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1777001811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1777001595"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1777001647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1777001622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1777001637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1777001993"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1777002058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1777001588"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1777002145"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1777001819"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1777001657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1777001578"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1777002721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1777001896"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1777001576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1777001621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1777001630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cli:1776999989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cli-artifacts:1777002317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cloud-credential-operator:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1777002062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1777001657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-autoscaler:1777001639"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1777001616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1777001722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-bootstrap:1777001579"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1777001660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1777001660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1777001584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-config-operator:1777001860"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1777001588"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-dns-operator:1777001846"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1777001876"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1777001943"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1777001611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1777001561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1777001575"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1777001571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1777002164"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-machine-approver:1777001580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1777001813"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-network-operator:1777001698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-node-tuning-operator:1777002719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1777001569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1777001603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1777001612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1777001775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-samples-operator:1777001570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-storage-operator:1777001574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-version-operator:1777001558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-configmap-reloader:1777001608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-console:1777002039"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-console-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1777001571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-coredns:1777001653"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1777001577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1777001777"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1777001621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1777001656"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1777001606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-attacher:1777001646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1777001646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-provisioner:1776999972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1776999972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-resizer:1776999948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1776999948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1776999951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1776999951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-livenessprobe:1776999947"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1776999947"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1776999949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1776999949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1777001741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1777001741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1777001992"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-docker-builder:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-docker-registry:1777001681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-etcd:1777001596"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1777001898"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1777002697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1777001692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1777001837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-hyperkube:1777304752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-hypershift-rhel8:1777001784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1777001854"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1777001574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1777001888"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1777001586"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1777001561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1777002168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1777001585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-installer:1777000374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-installer-artifacts:1777003222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1777001763"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1777001618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-proxy:1777001642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1776999981"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-state-metrics:1777001815"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1777001549"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1777001541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1777001647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1777001659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1777001636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1777001608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1777001598"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-config-operator:1777002732"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-admission-controller:1777001535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-cni:1777001584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1777001612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1777001628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1777001576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-must-gather:1777000645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1777002718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1777001624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-proxy:1777001606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1777002057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1777002697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1777002725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1777001617"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1777001581"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1777001775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1777001580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1777001618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-machine-controllers:1777001573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1777001630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-marketplace:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-registry:1777001671"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1777001649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovn-kubernetes:1777002178"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel8:1777001818"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-pod:1777304565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1777001521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1777001566"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1777001771"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1777042146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus:1777001745"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1777001893"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1777002720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1777001726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prom-label-proxy:1777001535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-sdn-rhel8:1777001790"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-service-ca-operator:1777001589"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-telemeter:1777001614"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-tests:1777002345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-thanos-rhel8:1777001839"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1777001605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1777001655"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1777001573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1777001605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1777001823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1777001631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1777001640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1777001645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-08T00:00:00Z",
        "advisory": "RHSA-2026:14100",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-tests:1778173182"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1779864120"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/egress-router-cni-rhel8:1779864235"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1779864128"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/network-tools-rhel8:1779313037"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1779889676"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1779889641"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1778765353"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1778765274"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel8:1779889723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1779863997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1779864079"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1779864508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1779864192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1779889720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1779863999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1779889660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1779889680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1779863969"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1779864074"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1779863989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1779889642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1779863994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1779864633"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1779864005"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1779889629"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1779889720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1779864603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1779863994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1779864132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1779864485"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cli:1779889704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cli-artifacts:1778765373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cloud-credential-operator:1779864236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1779889678"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1779864074"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-autoscaler:1779863413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1779864513"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1779864055"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-bootstrap:1779864189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1779864740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1779864740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1779864043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-config-operator:1779863993"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1779863952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1779864018"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-dns-operator:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1779863985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1779864123"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1779864006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1779863976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1779864264"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1779889616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1779889647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1779864436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-machine-approver:1779864047"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1779864102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-network-operator:1779889634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1779890827"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1779864733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1779864442"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1779864212"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1779889609"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-samples-operator:1779863398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-storage-operator:1779864003"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-version-operator:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-configmap-reloader:1779863974"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-console:1779864415"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-console-operator:1779889659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-coredns:1779864040"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1779889631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1779864020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1779864063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1779863966"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1779863998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1779864441"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-attacher:1779871348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1779871348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-provisioner:1779864793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1779864793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-resizer:1779864022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1779864022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1779864025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1779864025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-livenessprobe:1779864161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1779864161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1779864052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1779864052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1779889611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1779889611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1779889636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-docker-builder:1779863452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-docker-registry:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-etcd-rhel9:1779890788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1779864509"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1779864100"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1779889604"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1779863996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-hyperkube:1779864503"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-hypershift-rhel8:1779864639"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1779889658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1779864019"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1779889649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1779889642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1779864104"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1779863998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1779864066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1779864162"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-installer:1779864501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-installer-artifacts:1778766542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1779890216"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1779864028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-proxy:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1779889644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-state-metrics:1779864165"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1779889585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1779864651"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1779863394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1779864348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-operator:1779864206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1779864736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1779864245"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1779864151"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1779864229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-config-operator:1779864726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-admission-controller:1779864390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-cni:1779864023"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1779889657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1779863412"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1779863416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-must-gather:1778765257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1779864053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1779864236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel8:1779889646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1779864046"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1779864015"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-proxy:1779863392"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1779889638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1779889640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1779889694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1779863972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1779863952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1779864222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1779889602"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1779863995"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1779889649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-marketplace:1779864043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-registry:1779864451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1779864238"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes:1779891613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1779891537"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1779891613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-pod:1779864280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1779863962"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1779864153"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1779864168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1779864213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus:1779863444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1779863390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1779863389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-operator:1779864228"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1779864564"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prom-label-proxy:1779863397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-sdn-rhel8:1778765374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-service-ca-operator:1779864304"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-telemeter:1779889631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-tests:1779313164"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-thanos-rhel8:1779889664"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1779864199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1779864192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1779864001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1779864199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1779889644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1779864320"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1779889619"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1779889628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1777996897"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/egress-router-cni-rhel8:1777997332"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1777997462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/network-tools-rhel8:1778172521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1777997277"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1777996424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1777998220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1777997994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1777472634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1777996679"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1777472583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1777995469"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1777995698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1777995577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1777995808"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1777996402"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1777995599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1777995887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1777995699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1777995687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1777995600"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1777995569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1777995734"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1777995625"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1777995883"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1777995596"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1777995524"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1777995841"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel8:1777995603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1777996820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1777996330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1777997707"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1777997365"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cli:1777995604"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cli-artifacts:1777998025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cloud-credential-operator:1777996333"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1777996553"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1777995495"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-autoscaler:1777994910"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1777996723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1777997379"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-bootstrap:1777995458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1777997008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1777997008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1777996635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-config-operator:1777996776"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1777996381"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1777995506"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-dns-operator:1777995455"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1777996270"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1777996851"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1777996687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1777995760"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1777996782"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1777997020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1777997255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1777997210"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-machine-approver:1777995462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1777996292"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-network-operator:1778112812"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-node-tuning-operator:1777994001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1777994001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-olm-operator-rhel8:1777996262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1777997116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1777996254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1777996661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1777996509"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-samples-operator:1777994956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-storage-operator:1777997078"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-version-operator:1777997456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-configmap-reloader:1777996314"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-console:1777997704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-console-operator:1777997124"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1777997840"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-coredns:1777997281"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1777996831"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1777995492"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1777996366"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1777996486"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1777997218"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1777997375"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-attacher:1777995459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1777995459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-provisioner:1777995632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1777995632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-resizer:1777995652"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1777995652"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1777995784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1777995784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-livenessprobe:1777995463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1777995463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1777995491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1777995491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1777996342"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1777996342"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1777996315"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-docker-builder:1777995244"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-docker-registry:1777997725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-etcd-rhel9:1776786823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1777996755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1777996622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1777996228"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1777996220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1777472765"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-hypershift-rhel8:1778036600"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1777997038"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1777995572"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1777997296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1777995692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1777995653"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1777995573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1777995620"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1777996408"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-installer:1777996107"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-installer-artifacts:1778000857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1777994224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1777996885"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-proxy:1777995592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1777995480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-state-metrics:1777996287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1777996488"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1777997010"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1777994887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1777995962"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-operator:1777995710"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1777995601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1777995701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1777995520"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1777996613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-config-operator:1777997630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-admission-controller:1777997528"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-cni:1778170887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1777997407"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1777995116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1777995224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-must-gather:1777996785"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1777997235"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1777995460"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel8:1777995466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1777995484"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1777996597"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-proxy:1777995007"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1777997297"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-catalogd-rhel8:1777997176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel8:1777997205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1777997362"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1777997248"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1777995735"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1777997139"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1777997025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1777995629"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1777997265"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1777996400"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-marketplace:1777995482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-registry:1777995486"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1777997306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes:1778171006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1777950765"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1778171006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-pod:1777997313"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1777995498"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1777996700"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1777996514"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1777996741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus:1777995270"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1777994952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1777996409"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1777994918"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-operator:1777996333"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1777996709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prom-label-proxy:1777995205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-sdn-rhel8:1777998130"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-service-ca-operator:1777997562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-telemeter:1777997512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-tests:1777998461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-thanos-rhel8:1777996367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1777995461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1777995788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1777995630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1777995475"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1777995461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1777995788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1777995476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1777995464"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1777996582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1777997544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1777994657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/egress-router-cni-rhel8:1777994713"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/kube-metrics-server-rhel8:1777994576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1777994721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/network-tools-rhel8:1777998170"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1777519481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1777994523"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1777998000"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1777997820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1777478482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1777994504"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1777478234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel9:1777474101"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel9:1777474453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1777994483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel9:1777474227"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1777478096"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1777474127"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1777474416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1777474148"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1777474264"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1777474194"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1777474161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1777474315"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1777474158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1777994816"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1777474287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1777994712"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1777474440"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel8:1777994558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1778004053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1777518447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1777518423"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1777518340"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cli:1777994701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cli-artifacts:1777997939"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cloud-credential-operator:1777994673"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1777519328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1777519214"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1777518746"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1777518033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1777518321"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1777519394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1777519372"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1777518060"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1777478520"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1777519262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1777518061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1777478138"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1777519268"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1777518531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1777518280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1777519397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1777478065"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1777518472"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1777518634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1777518054"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1777518444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1777478122"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1777518753"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1778101510"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1777993307"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-olm-operator-rhel8:1777994508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1777518628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1777519168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel9:1777518056"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1777518330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1777519183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1777518052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1777518379"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1777478476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-console:1777994748"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-console-rhel9-operator:1777518836"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1777994759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-coredns-rhel9:1777518907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1777994680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1777476627"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1777477028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1777994803"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1777518277"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1777478042"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1777478430"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-provisioner:1777994744"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1777994744"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-resizer:1777994749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1777994749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1777474331"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-livenessprobe:1777994942"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1777994942"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1777994483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1777994483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1777518734"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1777518257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-docker-builder:1777993865"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1777518560"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-etcd-rhel9:1776790621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1777476910"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1777477747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1777994733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1777477500"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1777519044"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-hypershift-rhel9:1777560403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1777519438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1777474125"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1777474278"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1777994563"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1777474357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel9:1777474345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1777994558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1777518743"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer:1778003878"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer-altinfra-rhel8:1777995426"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer-artifacts:1778003967"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1777993546"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter-rhel9:1777478078"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1777519369"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1777994806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1777518797"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1777518058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1777518288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1777993309"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1777474219"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1777474262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1777477119"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1777518088"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1777519221"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-config-operator:1777994925"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1777478301"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-cni:1777994726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1777519086"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1777993775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1777993779"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-must-gather:1777995829"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1777994575"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1777519043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1777474308"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1777474367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1777518060"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1777518740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1777542478"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-catalogd-rhel8:1777994525"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel8:1777995008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1777994685"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1777518479"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1777518376"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1777519359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1777994467"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1777519284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1777519438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel8:1777994805"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1777545280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1777518048"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1777518565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1777950961"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1777951025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-pod-rhel9:1777518607"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1777994861"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1777476821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1777476388"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1777477330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus:1777993863"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1777993798"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1777478113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1777993796"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1777478254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1777518755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prom-label-proxy:1777993793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-sdn-rhel9:1777518582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1777478120"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-telemeter-rhel9:1777518059"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-tests:1777998234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-thanos-rhel8:1777994557"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1777994462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1777474367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1777474390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1777474189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1777994462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1777474367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1777474311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1777474366"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1777994505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1777478134"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1779262531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1779257059"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1779251936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1779257911"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/egress-router-cni-rhel9:1779252559"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1779263513"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1779258057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/network-tools-rhel9:1779269865"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1779252293"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1779255317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1779254514"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1779258263"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1779256917"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1779251346"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1779263613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel9:1779250446"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel9:1779250072"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1779263764"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1779250003"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1779250170"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1779250061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1779249996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1779250416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1779250137"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1779250036"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1779250124"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1779250177"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1779250039"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1779250067"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1779251456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1779250071"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1779269423"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1779256787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1779262505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1779254840"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1779261668"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cli-rhel9:1779253413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1779250856"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1779261997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1779256730"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1779250701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1779251982"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1779252065"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1779251832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1779263420"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1779258183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1779263384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1779259613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1779262272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1779252871"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1779252385"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1779258849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1779262399"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1779251986"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1779257509"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1779263748"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1779255692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1779258155"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1779263842"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1779251792"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1779250889"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1779258985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1779252665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1779258986"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1779263511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1779256025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1779259882"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1779253958"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1779259370"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1779263189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1779252337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-console-rhel9:1779258913"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-console-rhel9-operator:1779251959"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1779253897"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-coredns-rhel9:1779254114"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1779250591"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1779253593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1779253321"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1779258717"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9-operator:1779255989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1779250132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1779262779"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1779251129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1779253452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1779252626"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1779250200"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1779251358"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1779251893"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1779254156"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1779249986"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1779261706"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-etcd-rhel9:1779258224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1779251758"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1779254105"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1779250532"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1779251295"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1779263073"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-hypershift-rhel9:1779260812"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1779256393"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1779250211"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1779250499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1779250628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1779250592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1779250009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1779261020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1779281061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1779281084"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-rhel9:1779281052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1779249229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter-rhel9:1779253448"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1779251778"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1779252619"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1779252959"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1779252723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1779258382"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1779251500"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1779250152"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1779250032"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1779250449"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1779258721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1779252859"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1779252062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1779262789"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1779263539"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1779257736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1779250571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1779259043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1779254313"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-must-gather-rhel9:1779256131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1779261577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1779251811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1779250062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1779278543"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1779252089"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1779250609"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1779251536"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1779263779"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1779253467"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-rukpak-rhel9:1779263844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1779254455"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1779256815"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1779260915"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1779254907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1779252990"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1779250744"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1779253663"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1779263073"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1779260328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1779251927"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1779256134"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1779255831"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1779263069"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-pod-rhel9:1779250716"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1779251117"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1779253258"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1779251059"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1779251590"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1779255735"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1779262624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1779250747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1779251726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-rhel9:1779250180"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1779253852"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1779258763"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-sdn-rhel9:1779252050"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1779256002"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-telemeter-rhel9:1779251836"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-tests-rhel9:1779266539"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-thanos-rhel9:1779262189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-tools-rhel9:1779253265"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1779250064"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1779250066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1779249999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1779250085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1779250064"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1779250066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1779250033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1779250030"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1779262700"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1779254541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1778712094"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1778710338"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1778711456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1778710367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/driver-toolkit-rhel9:1778711050"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/egress-router-cni-rhel9:1778709318"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/frr-rhel9:1778701092"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1778711399"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1778711660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/network-tools-rhel9:1778718976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1778711674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1778711701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1778711791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1778711754"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1778711558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1778712111"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1778711782"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1778709420"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1778707346"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1778707380"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1778706811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1778707968"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1778707697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1778707580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1778706759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1778708031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1778708041"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1778707987"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1778707251"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1778707728"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1778707699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1778710129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1778718808"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1778711719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1778709794"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1778711768"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1778715516"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cli-rhel9:1778701275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1778710063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1778711773"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1778710542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1778710806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1778711741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1778709640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1778710891"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1778711802"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1778710438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1778710279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1778709692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1778709724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1778710173"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1778711613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1778709691"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1778711680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1778709871"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1778710213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1778711635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1778711609"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1778710421"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1778712033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1778710716"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1778709729"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1778710367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1778710661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1778709393"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1778710617"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1778709403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1778711783"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1778710126"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1778710517"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-update-keys-rhel9:1778709453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1778710545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1778710326"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-console-rhel9:1778718159"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-console-rhel9-operator:1778711749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1778710525"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-coredns-rhel9:1778710280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1778707878"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1778706645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1778707862"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1778710445"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9-operator:1778709335"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1778709792"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1778710349"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1778701149"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1778700996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1778700848"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1778700853"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1778700834"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1778709405"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1778710562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-deployer-rhel9:1778715239"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1778710258"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1778710229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-etcd-rhel9:1778709845"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1778708017"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1778707997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1778707723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1778708241"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1778711747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-haproxy-router-rhel9:1778711436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1778709689"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-hypershift-rhel9:1778710288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1778710227"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1778709545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1778711793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1778711557"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1778711683"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1778707299"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1778709453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1778711880"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1778710754"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-rhel9:1778710373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-agent-rhel9:1778706770"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1778707494"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-rhel9:1778707957"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-static-ip-manager-rhel9:1778707964"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-keepalived-ipfailover-rhel9:1778710806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1778711543"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1778701099"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1778709982"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1778710673"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1778710837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1778709447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1778707722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1778707724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1778707284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1778711757"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1778710857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1778711867"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-os-images-rhel9:1778718112"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1778718013"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1778711711"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1778711618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1778709750"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1778710823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1778711608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1778710881"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-must-gather-rhel9:1778702552"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-networking-console-plugin-rhel9:1778517109"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1778711621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1778710845"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1778707466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1778707832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1778710582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1778709208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1778709413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1778711551"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1778710351"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1778710181"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1778711581"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1778710026"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1778711478"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1778709328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1778711721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1778710093"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1778710263"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1778710541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1778709398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1778709325"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1778710391"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1778710176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-pod-rhel9:1778711650"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1778707884"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1778707466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1778706638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1778707549"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1778711553"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1778709872"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1778709287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1778709431"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-rhel9:1778710296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1778709906"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1778710862"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1778710475"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-telemeter-rhel9:1778711679"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-tests-rhel9:1778715654"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-thanos-rhel9:1778710497"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-tools-rhel9:1778701268"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1778707501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1778707849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1778707857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1778707857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1778707501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1778707849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1778707482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1778707873"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1778709987"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1778710215"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1776976672"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1776961463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/azure-service-rhel9-operator:1776960844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1776960917"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1776977459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/egress-router-cni-rhel9:1776961384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/frr-rhel9:1776959072"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1776960876"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1776961637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1776960951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1776961346"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/network-tools-rhel9:1777386789"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1776961082"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1776959659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1776977565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1776961890"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1776977144"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1776960584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1776959933"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1776961368"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1776959692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1776977206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1776959786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1776959689"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1776976655"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1776959839"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1776959747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1776959800"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1776959793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1776977166"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1776959648"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1776977216"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1776977062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1776961520"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1776978954"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1776960768"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1776959609"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1776960643"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1776978080"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cli-rhel9:1776977030"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1776959685"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1776977198"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1776977198"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1776959029"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1776976670"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1776976698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1776977468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1776977534"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1776960524"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1776959663"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1776977399"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1776976709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1776959644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1776960427"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1776960437"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1776960957"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1776977493"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1776960444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1776960581"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1776959626"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1776976718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1776977079"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1776959658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1776961740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1777458392"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1776991255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1776960373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1776960923"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1776977228"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1776960504"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1776959018"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1776961686"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1776976945"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1776960400"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9:1777459374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9-operator:1776960428"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1776976971"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-coredns-rhel9:1776977482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1776960303"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1776960803"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1776977219"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1776977506"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1776959982"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1776976955"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1776959614"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1776976688"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1776959903"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1776961239"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1776960688"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1777281183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1776961858"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-etcd-rhel9:1776977470"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1776977011"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1776960773"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1776960513"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1776960431"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1776959625"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1776976992"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hypershift-rhel9:1776960498"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1776977487"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1776959938"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1776959955"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1776959828"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1776959979"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1776959762"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1776960894"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1776964583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1776965622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-rhel9:1776965563"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1776977190"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1776960904"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1776977335"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1776976723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1776961689"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1776960536"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1776959685"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1776959695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1776977129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1776959665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1776960761"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1776961818"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1776961207"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1777465040"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1776976708"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1776976905"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1776961208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1776961238"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1776976705"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1776976709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-must-gather-rhel9:1776977949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1776961694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1776959624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1776959667"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1776959587"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1776959606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1776959028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1776959626"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1776976702"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1776977182"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1776959676"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1776959663"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1776961660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1776961613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1776976718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1776960383"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1776960407"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1776960542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1776961355"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1776961247"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1776960889"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1777287176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1777287257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-pod-rhel9:1776977214"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1777070108"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1777147660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1776977416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1776976659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1776961608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1776959615"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1776961144"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1776960661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9:1776976934"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1776976947"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1776977113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1776961226"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-telemeter-rhel9:1776960399"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tests-rhel9:1777386955"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-thanos-rhel9:1776961488"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tools-rhel9:1777377988"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1776959674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1776959663"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1776959671"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1776959634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1776959674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1776959663"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1776959660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1776976659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1776959666"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1776976721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13736",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tests-rhel9:1777553759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1776170839"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1776169938"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/network-tools-rhel9:1776231364"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1776171153"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1776168638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1776168580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1776168597"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1776168755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1776168548"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1776168731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1776172323"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1776170996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1776170085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1776169463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9:1776272700"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9-operator:1776168570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1776169866"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1776169550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1776140481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1776169045"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1776169220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1776131567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1776168778"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1776169657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hypershift-rhel9:1776168631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1776169271"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1776231376"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1776231752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1776231766"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-rhel9:1776231695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1776131777"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1776169412"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1776170255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1776170821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1776171076"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1776272397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1776170951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1776170749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1776170569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1776170491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1776170912"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1776170311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1776171922"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1776171907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1776169416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1776171002"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1776168565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1776169499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tests-rhel9:1776170901"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tools-rhel9:1776140622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1776168601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1776168580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1776168587"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1776168601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1772166986"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1772166701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1772168239"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-service-rhel9-operator:1772167793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1772167733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1772168057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/egress-router-cni-rhel9:1772168448"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/frr-rhel9:1772168092"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1772686533"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1772686690"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1772157106"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1772181061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/network-tools-rhel9:1773220587"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772716787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1772466901"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openstack-resource-controller-rhel9:1772166711"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1772181231"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1772168325"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772167317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1772157328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772166890"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772167008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772150798"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772150820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772149345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772149330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772150705"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772150844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772150771"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772150828"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772149306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1772150731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1772150759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772758175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1772151055"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1772167480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1772169582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1772168208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772167234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772167740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1772168967"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-rhel9:1772167409"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1772168373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772167462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772168176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772167544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772167861"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772167359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772167787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772167838"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772166959"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772167749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772168066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772166968"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772168113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772167859"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772167681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772167936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772157422"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772167226"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772181032"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1772167384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772595132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772168149"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772181009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1772709768"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772181022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1773215644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1772168183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772166718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772168076"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772181016"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772167789"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772477555"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772181012"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772167303"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9:1773096874"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772168220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1772168465"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-coredns-rhel9:1772181028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772154330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1772154031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772758170"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772167160"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1772166820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1772168206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772165961"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1772167933"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1772168079"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772181009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1772732473"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772167583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-etcd-rhel9:1772168302"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772154896"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772155817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1772154368"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772155114"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1772166752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772167456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hypershift-rhel9:1773125843"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772166192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772167204"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772166058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772758129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1772166233"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1772758160"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772165687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1772168742"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-rhel9:1772181272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1773057061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772181213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1772157180"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772167648"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772166097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772165479"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772165468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772151123"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772150802"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772155068"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772686568"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772166247"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1773184042"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1772709791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772165550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1772168198"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1772168446"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772686595"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1772166453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1772157220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-must-gather-rhel9:1772168903"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1772166450"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772165931"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772149183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772150968"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772166205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772167976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772167261"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1772165817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1772166052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772165925"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772166357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772166715"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772165985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1772165440"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772165924"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1772167832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1772595791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1772595334"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1772157323"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1772595900"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1773184641"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1773184785"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-pod-rhel9:1772168337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772758222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1772155094"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772154869"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772153399"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1772168339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772595658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1772168168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772595499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9:1772167208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772595786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1772166706"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772157057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772157116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tests-rhel9:1773220566"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-thanos-rhel9:1772157258"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tools-rhel9:1773215681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772758087"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1772150646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772686584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772150699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1772758087"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1772150646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772150660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772150954"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772166356"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772167335"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1772143108"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1772144253"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1772143861"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/azure-service-rhel9-operator:1772141804"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1772142576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1772144019"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/egress-router-cni-rhel9:1772143220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/frr-rhel9:1772143999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1772644085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1772644229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1772144695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1772141175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/network-tools-rhel9:1772595158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772574958"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1772144029"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/openstack-resource-controller-rhel9:1772143448"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1772523439"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1772523362"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772144004"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1772142177"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-ui-rhel9:1772138687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772142349"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772141184"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772138481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772138558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772138512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772138499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772138530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772138511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772138620"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772138530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772138605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1772138480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1772138526"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772138550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1772138504"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1772144786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1772655529"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1772144359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772143306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772142354"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1772524224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cli-rhel9:1772523269"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1772144014"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772142857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772144745"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772141413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772143467"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772574867"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772141541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772144616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772143505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772142729"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772144375"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772143219"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772141833"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772142083"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772141487"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772144675"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772141562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772144499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772144468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1772142357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772574880"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772143585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772142637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1772523242"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772142186"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1772593591"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1772143567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772143784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772143458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772141103"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772144434"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772141786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772143296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772142921"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-console-rhel9:1772142269"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772141663"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1772142278"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-coredns-rhel9:1772142665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772139730"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1772140894"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772141273"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772144699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1772142097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1772144027"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-snapshot-metadata-rhel9:1772144260"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772144056"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1772142266"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1772142511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772144436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1772143090"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772142447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-etcd-rhel9:1772143126"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772142217"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772141921"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1772140710"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772666832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1772143233"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772141417"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-hypershift-rhel9:1772574935"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772143941"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772138681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772138704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772139730"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1772144828"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1772490783"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772141241"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1772655389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-installer-rhel9:1772655272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1772593911"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772143650"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1772141436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772141284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772142819"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772142058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772141707"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772138490"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772138544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772142856"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772141988"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772143281"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1772608175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1772644163"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772143907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1772144363"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1772144275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772644153"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1772143637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1772144106"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-must-gather-rhel9:1772524101"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1772143661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772144523"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772138417"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772138382"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772141254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772144025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772574868"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1772144410"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1772142572"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772144691"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772142646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772141699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772666702"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1772143222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772141559"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1772143082"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1772176727"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1772176665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1772143531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1772176674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1772467275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1772523424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-pod-rhel9:1772143045"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772140895"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1772142175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772141519"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772143131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1772143435"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772433633"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1772144466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772433634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-rhel9:1772143543"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772433630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1772142820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772142573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772141358"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-tests-rhel9:1772655350"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-thanos-rhel9:1772141288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-tools-rhel9:1772593622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772138438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1772138413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772138401"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772138414"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772138437"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772138403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772141084"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772141210"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/volume-data-source-validator-rhel9:1772141838"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/istio-cni-rhel8:1771992208"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/istio-rhel8-operator:1771992461"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/pilot-rhel8:1771992212"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/ratelimit-rhel8:1771992437"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3556",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el9",
        "package": "openshift-service-mesh/proxyv2-rhel9:1772083861"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1774214116"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1774006090"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1774068855"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1774294372"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1774037349"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1774037369"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1774244136"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1774293851"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1774206585"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1774206464"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1774114903"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1774294809"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "golang",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-61731\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-61731\nhttps://go.dev/cl/736711\nhttps://go.dev/issue/77100\nhttps://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc\nhttps://pkg.go.dev/vuln/GO-2026-4339"
    ],
    "name": "CVE-2025-61731",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-02-05T03:42:26Z",
    "bugzilla": {
      "description": "cmd/cgo: Go cgo: Code smuggling due to comment parsing discrepancy",
      "id": "2437016",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2437016"
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "details": [
      "A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.",
      "A flaw was found in Go's 'cgo tool'. This vulnerability arises from a discrepancy in how Go and C/C++ comments are parsed, which allows for malicious code to be hidden within comments and then \"smuggled\" into the compiled `cgo` binary. An attacker could exploit this to embed and execute arbitrary code, potentially leading to significant system compromise."
    ],
    "statement": "This is an Important vulnerability in the `cmd/cgo` component of the Go toolchain. A parsing discrepancy between Go and C/C++ comments could allow for code smuggling into the resulting `cgo` binary. This primarily affects systems where untrusted Go modules utilizing `cgo` are built, impacting Red Hat Enterprise Linux and OpenShift Container Platform.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2706",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "golang-0:1.25.7-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3192",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "golang-0:1.25.7-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2708",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "go-toolset:rhel8-8100020260212045823.a3795dee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3468",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "go-toolset:rhel8-8020020260227115231.02f7cb7a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3470",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "go-toolset:rhel8-8040020260227112052.5081a262"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3470",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "go-toolset:rhel8-8040020260227112052.5081a262"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3489",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "go-toolset:rhel8-8060020260227122329.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3489",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "go-toolset:rhel8-8060020260227122329.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3489",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "go-toolset:rhel8-8060020260227122329.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3471",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "go-toolset:rhel8-8080020260227110256.6b4b45d8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3471",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "go-toolset:rhel8-8080020260227110256.6b4b45d8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2709",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "golang-0:1.25.7-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3473",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "golang-0:1.17.13-10.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3472",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "golang-0:1.19.13-23.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3469",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "golang-0:1.21.13-14.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3193",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "golang-0:1.25.7-1.el9_6"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7291",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-26-main-1.26.2-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7385",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-25-main-1.25.9-1.hum1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1777002694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/egress-router-cni-rhel8:1777001625"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1777001562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/network-tools-rhel8:1777002936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1777042122"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1777001567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1777002279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1777002206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel8:1777001821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1777002716"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1777001811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1777001595"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1777001647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1777001622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1777001637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1777001993"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1777002058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1777001588"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1777002145"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1777001819"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1777001657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1777001578"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1777002721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1777001896"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1777001576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1777001621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1777001630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cli:1776999989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cli-artifacts:1777002317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cloud-credential-operator:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1777002062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1777001657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-autoscaler:1777001639"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1777001616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1777001722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-bootstrap:1777001579"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1777001660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1777001660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1777001584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-config-operator:1777001860"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1777001588"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-dns-operator:1777001846"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1777001876"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1777001943"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1777001611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1777001561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1777001575"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1777001571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1777002164"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-machine-approver:1777001580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1777001813"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-network-operator:1777001698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-node-tuning-operator:1777002719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1777001569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1777001603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1777001612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1777001775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-samples-operator:1777001570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-storage-operator:1777001574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-version-operator:1777001558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-configmap-reloader:1777001608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-console:1777002039"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-console-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1777001571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-coredns:1777001653"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1777001577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1777001777"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1777001621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1777001656"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1777001606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-attacher:1777001646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1777001646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-provisioner:1776999972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1776999972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-resizer:1776999948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1776999948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1776999951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1776999951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-livenessprobe:1776999947"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1776999947"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1776999949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1776999949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1777001741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1777001741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1777001992"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-docker-builder:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-docker-registry:1777001681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-etcd:1777001596"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1777001898"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1777002697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1777001692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1777001837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-hyperkube:1777304752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-hypershift-rhel8:1777001784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1777001854"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1777001574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1777001888"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1777001586"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1777001561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1777002168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1777001585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-installer:1777000374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-installer-artifacts:1777003222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1777001763"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1777001618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-proxy:1777001642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1776999981"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-state-metrics:1777001815"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1777001549"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1777001541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1777001647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1777001659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1777001636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1777001608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1777001598"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-config-operator:1777002732"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-admission-controller:1777001535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-cni:1777001584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1777001612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1777001628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1777001576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-must-gather:1777000645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1777002718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1777001624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-proxy:1777001606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1777002057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1777002697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1777002725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1777001617"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1777001581"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1777001775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1777001580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1777001618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-machine-controllers:1777001573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1777001630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-marketplace:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-registry:1777001671"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1777001649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovn-kubernetes:1777002178"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel8:1777001818"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-pod:1777304565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1777001521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1777001566"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1777001771"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1777042146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus:1777001745"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1777001893"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1777002720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1777001726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prom-label-proxy:1777001535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-sdn-rhel8:1777001790"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-service-ca-operator:1777001589"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-telemeter:1777001614"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-tests:1777002345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-thanos-rhel8:1777001839"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1777001605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1777001655"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1777001573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1777001605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1777001823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1777001631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1777001640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1777001645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-08T00:00:00Z",
        "advisory": "RHSA-2026:14100",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-tests:1778173182"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1779864120"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/egress-router-cni-rhel8:1779864235"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1779864128"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/network-tools-rhel8:1779313037"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1779889676"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1779889641"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1778765353"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1778765274"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel8:1779889723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1779863997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1779864079"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1779864508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1779864192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1779889720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1779863999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1779889660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1779889680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1779863969"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1779864074"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1779863989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1779889642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1779863994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1779864633"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1779864005"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1779889629"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1779889720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1779864603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1779863994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1779864132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1779864485"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cli:1779889704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cli-artifacts:1778765373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cloud-credential-operator:1779864236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1779889678"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1779864074"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-autoscaler:1779863413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1779864513"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1779864055"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-bootstrap:1779864189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1779864740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1779864740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1779864043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-config-operator:1779863993"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1779863952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1779864018"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-dns-operator:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1779863985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1779864123"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1779864006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1779863976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1779864264"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1779889616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1779889647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1779864436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-machine-approver:1779864047"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1779864102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-network-operator:1779889634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1779890827"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1779864733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1779864442"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1779864212"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1779889609"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-samples-operator:1779863398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-storage-operator:1779864003"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-version-operator:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-configmap-reloader:1779863974"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-console:1779864415"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-console-operator:1779889659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-coredns:1779864040"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1779889631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1779864020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1779864063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1779863966"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1779863998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1779864441"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-attacher:1779871348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1779871348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-provisioner:1779864793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1779864793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-resizer:1779864022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1779864022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1779864025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1779864025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-livenessprobe:1779864161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1779864161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1779864052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1779864052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1779889611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1779889611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1779889636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-docker-builder:1779863452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-docker-registry:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-etcd-rhel9:1779890788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1779864509"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1779864100"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1779889604"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1779863996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-hyperkube:1779864503"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-hypershift-rhel8:1779864639"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1779889658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1779864019"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1779889649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1779889642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1779864104"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1779863998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1779864066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1779864162"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-installer:1779864501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-installer-artifacts:1778766542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1779890216"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1779864028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-proxy:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1779889644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-state-metrics:1779864165"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1779889585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1779864651"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1779863394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1779864348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-operator:1779864206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1779864736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1779864245"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1779864151"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1779864229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-config-operator:1779864726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-admission-controller:1779864390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-cni:1779864023"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1779889657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1779863412"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1779863416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-must-gather:1778765257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1779864053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1779864236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel8:1779889646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1779864046"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1779864015"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-proxy:1779863392"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1779889638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1779889640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1779889694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1779863972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1779863952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1779864222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1779889602"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1779863995"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1779889649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-marketplace:1779864043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-registry:1779864451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1779864238"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes:1779891613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1779891537"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1779891613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-pod:1779864280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1779863962"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1779864153"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1779864168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1779864213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus:1779863444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1779863390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1779863389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-operator:1779864228"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1779864564"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prom-label-proxy:1779863397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-sdn-rhel8:1778765374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-service-ca-operator:1779864304"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-telemeter:1779889631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-tests:1779313164"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-thanos-rhel8:1779889664"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1779864199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1779864192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1779864001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1779864199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1779889644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1779864320"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1779889619"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1779889628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1777996897"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/egress-router-cni-rhel8:1777997332"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1777997462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/network-tools-rhel8:1778172521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1777997277"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1777996424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1777998220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1777997994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1777472634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1777996679"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1777472583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1777995469"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1777995698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1777995577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1777995808"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1777996402"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1777995599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1777995887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1777995699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1777995687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1777995600"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1777995569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1777995734"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1777995625"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1777995883"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1777995596"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1777995524"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1777995841"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel8:1777995603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1777996820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1777996330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1777997707"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1777997365"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cli:1777995604"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cli-artifacts:1777998025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cloud-credential-operator:1777996333"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1777996553"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1777995495"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-autoscaler:1777994910"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1777996723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1777997379"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-bootstrap:1777995458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1777997008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1777997008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1777996635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-config-operator:1777996776"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1777996381"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1777995506"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-dns-operator:1777995455"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1777996270"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1777996851"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1777996687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1777995760"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1777996782"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1777997020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1777997255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1777997210"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-machine-approver:1777995462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1777996292"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-network-operator:1778112812"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-node-tuning-operator:1777994001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1777994001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-olm-operator-rhel8:1777996262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1777997116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1777996254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1777996661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1777996509"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-samples-operator:1777994956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-storage-operator:1777997078"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-version-operator:1777997456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-configmap-reloader:1777996314"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-console:1777997704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-console-operator:1777997124"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1777997840"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-coredns:1777997281"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1777996831"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1777995492"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1777996366"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1777996486"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1777997218"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1777997375"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-attacher:1777995459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1777995459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-provisioner:1777995632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1777995632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-resizer:1777995652"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1777995652"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1777995784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1777995784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-livenessprobe:1777995463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1777995463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1777995491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1777995491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1777996342"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1777996342"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1777996315"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-docker-builder:1777995244"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-docker-registry:1777997725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-etcd-rhel9:1776786823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1777996755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1777996622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1777996228"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1777996220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1777472765"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-hypershift-rhel8:1778036600"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1777997038"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1777995572"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1777997296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1777995692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1777995653"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1777995573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1777995620"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1777996408"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-installer:1777996107"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-installer-artifacts:1778000857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1777994224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1777996885"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-proxy:1777995592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1777995480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-state-metrics:1777996287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1777996488"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1777997010"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1777994887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1777995962"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-operator:1777995710"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1777995601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1777995701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1777995520"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1777996613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-config-operator:1777997630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-admission-controller:1777997528"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-cni:1778170887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1777997407"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1777995116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1777995224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-must-gather:1777996785"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1777997235"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1777995460"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel8:1777995466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1777995484"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1777996597"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-proxy:1777995007"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1777997297"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-catalogd-rhel8:1777997176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel8:1777997205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1777997362"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1777997248"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1777995735"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1777997139"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1777997025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1777995629"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1777997265"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1777996400"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-marketplace:1777995482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-registry:1777995486"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1777997306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes:1778171006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1777950765"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1778171006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-pod:1777997313"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1777995498"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1777996700"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1777996514"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1777996741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus:1777995270"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1777994952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1777996409"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1777994918"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-operator:1777996333"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1777996709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prom-label-proxy:1777995205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-sdn-rhel8:1777998130"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-service-ca-operator:1777997562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-telemeter:1777997512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-tests:1777998461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-thanos-rhel8:1777996367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1777995461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1777995788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1777995630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1777995475"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1777995461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1777995788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1777995476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1777995464"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1777996582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1777997544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1777994657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/egress-router-cni-rhel8:1777994713"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/kube-metrics-server-rhel8:1777994576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1777994721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/network-tools-rhel8:1777998170"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1777519481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1777994523"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1777998000"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1777997820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1777478482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1777994504"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1777478234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel9:1777474101"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel9:1777474453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1777994483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel9:1777474227"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1777478096"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1777474127"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1777474416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1777474148"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1777474264"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1777474194"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1777474161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1777474315"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1777474158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1777994816"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1777474287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1777994712"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1777474440"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel8:1777994558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1778004053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1777518447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1777518423"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1777518340"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cli:1777994701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cli-artifacts:1777997939"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cloud-credential-operator:1777994673"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1777519328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1777519214"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1777518746"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1777518033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1777518321"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1777519394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1777519372"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1777518060"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1777478520"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1777519262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1777518061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1777478138"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1777519268"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1777518531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1777518280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1777519397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1777478065"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1777518472"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1777518634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1777518054"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1777518444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1777478122"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1777518753"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1778101510"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1777993307"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-olm-operator-rhel8:1777994508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1777518628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1777519168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel9:1777518056"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1777518330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1777519183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1777518052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1777518379"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1777478476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-console:1777994748"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-console-rhel9-operator:1777518836"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1777994759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-coredns-rhel9:1777518907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1777994680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1777476627"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1777477028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1777994803"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1777518277"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1777478042"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1777478430"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-provisioner:1777994744"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1777994744"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-resizer:1777994749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1777994749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1777474331"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-livenessprobe:1777994942"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1777994942"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1777994483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1777994483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1777518734"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1777518257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-docker-builder:1777993865"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1777518560"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-etcd-rhel9:1776790621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1777476910"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1777477747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1777994733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1777477500"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1777519044"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-hypershift-rhel9:1777560403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1777519438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1777474125"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1777474278"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1777994563"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1777474357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel9:1777474345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1777994558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1777518743"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer:1778003878"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer-altinfra-rhel8:1777995426"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer-artifacts:1778003967"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1777993546"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter-rhel9:1777478078"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1777519369"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1777994806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1777518797"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1777518058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1777518288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1777993309"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1777474219"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1777474262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1777477119"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1777518088"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1777519221"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-config-operator:1777994925"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1777478301"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-cni:1777994726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1777519086"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1777993775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1777993779"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-must-gather:1777995829"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1777994575"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1777519043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1777474308"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1777474367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1777518060"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1777518740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1777542478"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-catalogd-rhel8:1777994525"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel8:1777995008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1777994685"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1777518479"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1777518376"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1777519359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1777994467"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1777519284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1777519438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel8:1777994805"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1777545280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1777518048"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1777518565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1777950961"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1777951025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-pod-rhel9:1777518607"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1777994861"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1777476821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1777476388"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1777477330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus:1777993863"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1777993798"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1777478113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1777993796"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1777478254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1777518755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prom-label-proxy:1777993793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-sdn-rhel9:1777518582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1777478120"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-telemeter-rhel9:1777518059"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-tests:1777998234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-thanos-rhel8:1777994557"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1777994462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1777474367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1777474390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1777474189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1777994462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1777474367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1777474311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1777474366"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1777994505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1777478134"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1776727891"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1776699297"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1776728824"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1776727904"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/egress-router-cni-rhel9:1776698563"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1776698624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1776699337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/network-tools-rhel9:1776731043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1776728960"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1776698978"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1776728421"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1776728312"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1776699634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1776699073"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1776728900"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel9:1776697731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel9:1776697719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1776728874"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1776697791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1776697844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1776697799"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1776697771"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1776697837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1776697806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1776697826"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1776697897"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1776697818"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1776697884"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1776697747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1776698735"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1776697825"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1776731113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1776698623"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1776728462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1776699205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1776728072"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cli-rhel9:1776697824"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1776782168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1776698632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1776728357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1776697163"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1776728167"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1776698905"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1776699430"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1776729175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1776699431"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1776699567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1776728154"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1776727801"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1776729050"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1776698337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1776729221"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1776699025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1776728759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1776727905"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1776728036"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1776727910"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1776699521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1776698913"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1776728010"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1776728853"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1776698638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1776729344"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1776728572"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1776728832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1776728728"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1776729115"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1776697180"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1776698874"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1776699128"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1776699189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-console-rhel9:1776827996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-console-rhel9-operator:1776698489"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1776728544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-coredns-rhel9:1776728186"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1776698522"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1776698476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1776698326"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1776729216"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9-operator:1776729099"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1776698985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1776729115"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1776697827"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1776697832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1776697815"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1776697847"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1776697751"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1776729182"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1776698953"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1776697230"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1776728148"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-etcd-rhel9:1776728306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1776698867"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1776698923"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1776698411"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1776698860"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1776728691"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-hypershift-rhel9:1776699376"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1776699740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1776699171"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1776699502"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1776698051"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1776697914"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1776697838"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1776699264"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1776729530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1776734891"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-rhel9:1776734824"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1776827300"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter-rhel9:1776728619"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1776728364"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1776697847"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1776727790"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1776699541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1776698615"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1776729041"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1776697851"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1776697847"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1776698490"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1776699411"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1776699226"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1776699250"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1776698529"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1776698678"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1776698674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1776699303"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1776698645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1776698545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-must-gather-rhel9:1776698851"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1776698463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1776699089"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1776697723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1776697725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1776727937"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1776697196"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1776699112"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1776698518"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1776727948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-rukpak-rhel9:1776728796"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1776698402"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1776728576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1776727924"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1776727875"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1776728631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1776699637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1776699410"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1776729034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1776699635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1776728529"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1776728041"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1776869755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1776869821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-pod-rhel9:1776729175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1776698970"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1776698927"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1776698929"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1776698339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1776699552"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1776698599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1776699247"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1776729049"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-rhel9:1776699050"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1776699182"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1776699224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-sdn-rhel9:1776699232"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1776699071"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-telemeter-rhel9:1776728887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-tests-rhel9:1776728272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-thanos-rhel9:1776728595"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-tools-rhel9:1776697962"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1776697733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1776697721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1776697724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1776697756"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1776697733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1776697721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1776697723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1776697728"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1776727833"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10104",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1776729097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1778712094"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1778710338"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1778711456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1778710367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/driver-toolkit-rhel9:1778711050"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/egress-router-cni-rhel9:1778709318"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/frr-rhel9:1778701092"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1778711399"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1778711660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/network-tools-rhel9:1778718976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1778711674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1778711701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1778711791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1778711754"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1778711558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1778712111"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1778711782"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1778709420"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1778707346"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1778707380"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1778706811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1778707968"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1778707697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1778707580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1778706759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1778708031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1778708041"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1778707987"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1778707251"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1778707728"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1778707699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1778710129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1778718808"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1778711719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1778709794"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1778711768"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1778715516"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cli-rhel9:1778701275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1778710063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1778711773"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1778710542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1778710806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1778711741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1778709640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1778710891"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1778711802"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1778710438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1778710279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1778709692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1778709724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1778710173"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1778711613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1778709691"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1778711680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1778709871"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1778710213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1778711635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1778711609"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1778710421"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1778712033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1778710716"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1778709729"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1778710367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1778710661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1778709393"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1778710617"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1778709403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1778711783"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1778710126"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1778710517"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-update-keys-rhel9:1778709453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1778710545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1778710326"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-console-rhel9:1778718159"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-console-rhel9-operator:1778711749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1778710525"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-coredns-rhel9:1778710280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1778707878"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1778706645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1778707862"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1778710445"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9-operator:1778709335"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1778709792"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1778710349"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1778701149"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1778700996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1778700848"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1778700853"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1778700834"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1778709405"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1778710562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-deployer-rhel9:1778715239"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1778710258"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1778710229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-etcd-rhel9:1778709845"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1778708017"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1778707997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1778707723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1778708241"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1778711747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-haproxy-router-rhel9:1778711436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1778709689"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-hypershift-rhel9:1778710288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1778710227"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1778709545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1778711793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1778711557"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1778711683"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1778707299"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1778709453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1778711880"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1778710754"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-rhel9:1778710373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-agent-rhel9:1778706770"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1778707494"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-rhel9:1778707957"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-static-ip-manager-rhel9:1778707964"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-keepalived-ipfailover-rhel9:1778710806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1778711543"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1778701099"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1778709982"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1778710673"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1778710837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1778709447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1778707722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1778707724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1778707284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1778711757"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1778710857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1778711867"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-os-images-rhel9:1778718112"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1778718013"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1778711711"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1778711618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1778709750"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1778710823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1778711608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1778710881"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-must-gather-rhel9:1778702552"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-networking-console-plugin-rhel9:1778517109"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1778711621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1778710845"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1778707466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1778707832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1778710582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1778709208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1778709413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1778711551"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1778710351"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1778710181"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1778711581"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1778710026"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1778711478"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1778709328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1778711721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1778710093"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1778710263"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1778710541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1778709398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1778709325"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1778710391"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1778710176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-pod-rhel9:1778711650"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1778707884"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1778707466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1778706638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1778707549"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1778711553"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1778709872"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1778709287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1778709431"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-rhel9:1778710296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1778709906"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1778710862"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1778710475"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-telemeter-rhel9:1778711679"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-tests-rhel9:1778715654"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-thanos-rhel9:1778710497"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-tools-rhel9:1778701268"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1778707501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1778707849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1778707857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1778707857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1778707501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1778707849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1778707482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1778707873"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1778709987"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1778710215"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1776170198"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1776169760"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/azure-service-rhel9-operator:1776170499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1776168588"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1776170152"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/egress-router-cni-rhel9:1776170384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/frr-rhel9:1776131530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1776170839"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1776169938"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1776168574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1776170196"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/network-tools-rhel9:1776231364"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1776170145"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1776170559"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1776171153"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1776168736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1776170782"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1776170252"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1776168732"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1776170114"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1776168550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1776168638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1776132568"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1776168580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1776168651"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1776168624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1776168767"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1776168597"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1776168895"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1776168755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1776168548"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1776168731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1776132609"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1776169713"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1776172323"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1776170202"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1776168562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1776168831"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1776232352"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cli-rhel9:1776231245"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1776170903"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1776170565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1776170263"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1776131462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1776168550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1776169487"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1776169983"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1776169648"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1776169767"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1776168577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1776169893"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1776169336"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1776170468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1776169542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1776169742"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1776168593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1776170567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1776169891"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1776168632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1776170190"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1776170091"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1776170952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1776169545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1776170996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1776169784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1776170085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1776168556"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1776170658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1776168560"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1776169652"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1776131421"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1776168603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1776169463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1776168548"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9:1776272700"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9-operator:1776168570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1776170010"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-coredns-rhel9:1776169516"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1776168595"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1776169866"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1776169550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1776168562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1776140481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1776169190"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1776169115"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1776169045"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1776169220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1776170274"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1776168568"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1776131567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1776168778"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-etcd-rhel9:1776170695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1776168615"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1776169657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1776169651"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1776170347"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1776170249"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1776170394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hypershift-rhel9:1776168631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1776168620"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1776169955"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1776170954"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1776169271"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1776231287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1776231376"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1776168603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1776231752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1776231766"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-rhel9:1776231695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1776131777"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1776169681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1776168604"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1776170129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1776169412"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1776169476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1776170183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1776168597"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1776132551"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1776170257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1776170255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1776170821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1776171076"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1776272397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1776169673"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1776170951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1776170749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1776169676"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1776170626"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1776170302"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-must-gather-rhel9:1776232238"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1776169460"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1776169395"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1776168597"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1776168580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1776168571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1776131461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1776169608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1776169764"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1776170545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1776170382"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1776170029"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1776168549"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1776170034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1776170569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1776170932"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1776168627"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1776170491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1776170912"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1776170142"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1776170311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1776171922"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1776171907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-pod-rhel9:1776170880"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1776169416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1776170365"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1776168565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1776169834"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1776168629"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1776171002"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1776169614"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1776168565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9:1776168894"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1776169499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1776168651"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1776170861"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-telemeter-rhel9:1776170292"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tests-rhel9:1776170901"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-thanos-rhel9:1776170891"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tools-rhel9:1776140622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1776168601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1776168603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1776168580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1776168587"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1776168601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1776168603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1776168574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1776168584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1776170292"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1776169493"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1772166986"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1772166701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1772168239"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-service-rhel9-operator:1772167793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1772167733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1772168057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/egress-router-cni-rhel9:1772168448"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/frr-rhel9:1772168092"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1772686533"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1772686690"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1772157106"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1772181061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/network-tools-rhel9:1773220587"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772716787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1772466901"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openstack-resource-controller-rhel9:1772166711"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1772181231"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1772168325"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772167317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1772157328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772166890"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772167008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772150798"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772150820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772149345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772149330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772150705"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772150844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772150771"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772150828"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772149306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1772150731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1772150759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772758175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1772151055"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1772167480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1772169582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1772168208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772167234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772167740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1772168967"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1772168373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772167462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772168176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772167544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772167861"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772167359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772167787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772167838"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772166959"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772167749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772168066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772166968"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772168113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772167859"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772167681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772167936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772157422"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772167226"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772181032"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1772167384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772595132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772168149"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772181009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1772709768"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772181022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1773215644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1772168183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772166718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772168076"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772181016"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772167789"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772477555"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772181012"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772167303"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9:1773096874"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772168220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1772168465"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-coredns-rhel9:1772181028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772154330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1772154031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772758170"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772167160"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1772166820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1772168206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772165961"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1772167933"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1772168079"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772181009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1772732473"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772167583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-etcd-rhel9:1772168302"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772154896"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772155817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1772154368"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772155114"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1772166752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772167456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hypershift-rhel9:1773125843"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772166192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772167204"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772166058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772758129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1772166233"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1772758160"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772165687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1772168742"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-rhel9:1772181272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1773057061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772181213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1772157180"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772167648"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772166097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772165479"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772165468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772151123"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772150802"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772155068"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772686568"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772166247"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1773184042"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1772709791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772165550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1772168198"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1772168446"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772686595"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1772166453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1772157220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-must-gather-rhel9:1772168903"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1772166450"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772165931"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772149183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772150968"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772166205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772167976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772167261"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1772165817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1772166052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772165925"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772166357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772166715"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772165985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1772165440"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772165924"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1772167832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1772595791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1772595334"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1772157323"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1772595900"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1773184641"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1773184785"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-pod-rhel9:1772168337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772758222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1772155094"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772154869"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772153399"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1772168339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772595658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1772168168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772595499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9:1772167208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772595786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1772166706"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772157057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772157116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tests-rhel9:1773220566"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-thanos-rhel9:1772157258"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tools-rhel9:1773215681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772758087"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1772150646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772686584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772150699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1772758087"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1772150646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772150660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772150954"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772166356"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772167335"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:5878",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-rhel9:1774287072"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1772143108"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1772144253"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1772143861"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/azure-service-rhel9-operator:1772141804"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1772142576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1772144019"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/egress-router-cni-rhel9:1772143220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/frr-rhel9:1772143999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1772644085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1772644229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1772144695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1772141175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/network-tools-rhel9:1772595158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772574958"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1772144029"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/openstack-resource-controller-rhel9:1772143448"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1772523439"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1772523362"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772144004"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1772142177"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-ui-rhel9:1772138687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772142349"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772141184"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772138481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772138558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772138512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772138499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772138530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772138511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772138620"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772138530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772138605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1772138480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1772138526"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772138550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1772138504"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1772144786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1772655529"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1772144359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772143306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772142354"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1772524224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cli-rhel9:1772523269"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1772144014"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772142857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772144745"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772141413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772143467"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772574867"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772141541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772144616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772143505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772142729"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772144375"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772143219"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772141833"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772142083"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772141487"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772144675"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772141562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772144499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772144468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1772142357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772574880"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772143585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772142637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1772523242"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772142186"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1772593591"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1772143567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772143784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772143458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772141103"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772144434"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772141786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772143296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772142921"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-console-rhel9:1772142269"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772141663"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1772142278"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-coredns-rhel9:1772142665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772139730"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1772140894"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772141273"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772144699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1772142097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1772144027"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-snapshot-metadata-rhel9:1772144260"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772144056"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1772142266"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1772142511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772144436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1772143090"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772142447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-etcd-rhel9:1772143126"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772142217"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772141921"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1772140710"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772666832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1772143233"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772141417"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-hypershift-rhel9:1772574935"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772143941"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772138681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772138704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772139730"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1772144828"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1772490783"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772141241"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1772655389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-installer-rhel9:1772655272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1772593911"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772143650"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1772141436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772141284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772142819"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772142058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772141707"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772138490"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772138544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772142856"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772141988"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772143281"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1772608175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1772644163"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772143907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1772144363"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1772144275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772644153"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1772143637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1772144106"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-must-gather-rhel9:1772524101"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1772143661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772144523"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772138417"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772138382"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772141254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772144025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772574868"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1772144410"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1772142572"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772144691"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772142646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772141699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772666702"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1772143222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772141559"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1772143082"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1772176727"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1772176665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1772143531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1772176674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1772467275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1772523424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-pod-rhel9:1772143045"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772140895"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1772142175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772141519"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772143131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1772143435"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772433633"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1772144466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772433634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-rhel9:1772143543"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772433630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1772142820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772142573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772141358"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-tests-rhel9:1772655350"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-thanos-rhel9:1772141288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-tools-rhel9:1772593622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772138438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1772138413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772138401"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772138414"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772138437"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772138403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772141084"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772141210"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/volume-data-source-validator-rhel9:1772141838"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces (RHOSDS) 3.26",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2844",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.26::el9",
        "package": "devspaces/udi-rhel9:1770913862"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/istio-cni-rhel8:1771992208"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/istio-rhel8-operator:1771992461"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/pilot-rhel8:1771992212"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/ratelimit-rhel8:1771992437"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3556",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el9",
        "package": "openshift-service-mesh/proxyv2-rhel9:1772083861"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1774214116"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1774006090"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1774068855"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1774294372"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1774037349"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1774037369"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1774244136"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1774293851"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1774206585"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1774206464"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1774114903"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1774294809"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "go-toolset",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-61732\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-61732\nhttps://go.dev/cl/734220\nhttps://go.dev/issue/76697\nhttps://groups.google.com/g/golang-announce/c/K09ubi9FQFk\nhttps://pkg.go.dev/vuln/GO-2026-4433"
    ],
    "name": "CVE-2025-61732",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-11-07T04:15:09Z",
    "bugzilla": {
      "description": "github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaks",
      "id": "2413299",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2413299"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-771",
    "details": [
      "containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.",
      "A flaw was found in containerd. This vulnerability allows a user to exhaust memory on the host due to goroutine leaks via a bug in the CRI (Container Runtime Interface) Attach implementation."
    ],
    "statement": "The highest threat of this vulnerability is to system availability. A flaw in containerd's CRI Attach implementation allows a user to exhaust memory on the host due to goroutine leaks, leading to a denial of service.",
    "affected_release": [
      {
        "product_name": "Network Observability (NETOBSERV) 1.11.1",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2900",
        "cpe": "cpe:/a:redhat:network_observ_optr:1.11::el9",
        "package": "network-observability/network-observability-cli-rhel9:1771226060"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/cephcsi-rhel9:1782932114"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/cephcsi-rhel9-operator:1782931768"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/devicefinder-rhel9:1782932104"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/mcg-core-rhel9:1783536000"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/mcg-rhel9-operator:1783535989"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-client-console-rhel9:1783536515"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-client-rhel9-operator:1782932521"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1783018461"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-rhel9-operator:1783018421"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-blackbox-exporter-rhel9:1782932812"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cli-rhel9:1783537001"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1782932919"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-console-rhel9:1783537586"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1782932969"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1782933015"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1782933042"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-drbd-rhel9:1783537392"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-external-snapshotter-rhel9-operator:1782933235"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-external-snapshotter-sidecar-rhel9:1782933251"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1783537955"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1782933417"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-must-gather-rhel9:1783537742"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-rhel9-operator:1782933602"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-rhel9-operator:1783019377"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-volsync-plugin-mover-rhel9:1782934054"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-volsync-plugin-rhel9-operator:1782934036"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1782934284"
      }
    ],
    "package_state": [
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "assisted/agent-preinstall-image-builder-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "rhai/assisted-installer-agent-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "rhai/assisted-installer-controller-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Compliance Operator",
        "fix_state": "Affected",
        "package_name": "compliance/openshift-compliance-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "openshift-sandboxed-containers/osc-monitor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "openshift-sandboxed-containers/osc-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Custom Metric Autoscaler operator for Red Hat Openshift",
        "fix_state": "Affected",
        "package_name": "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
      },
      {
        "product_name": "Deployment Validation Operator",
        "fix_state": "Affected",
        "package_name": "dvo/deployment-validation-rhel8-operator",
        "cpe": "cpe:/a:redhat:deployment_validator_operator"
      },
      {
        "product_name": "File Integrity Operator",
        "fix_state": "Affected",
        "package_name": "compliance/openshift-compliance-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1"
      },
      {
        "product_name": "Gatekeeper 3",
        "fix_state": "Affected",
        "package_name": "gatekeeper/gatekeeper-rhel9",
        "cpe": "cpe:/a:redhat:gatekeeper:3"
      },
      {
        "product_name": "Kernel Module Management Operator for Red Hat Openshift",
        "fix_state": "Affected",
        "package_name": "kmm/kernel-module-management-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:kernel_module_management:2"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/loki-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/loki-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/lokistack-gateway-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/opa-openshift-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/loki-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/loki-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/lokistack-gateway-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/opa-openshift-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Affected",
        "package_name": "lvms4/lvms-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/machine-deletion-remediation-operator-bundle",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/machine-deletion-remediation-rhel9-operator",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-hook-runner-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-log-reader-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-api-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-cli-download-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-openstack-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-operator-bundle",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-ova-provider-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-ova-proxy-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-populator-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-rhv-populator-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-validation-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-virt-v2v-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-vsphere-xcopy-volume-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-api-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-cli-download-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-openstack-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-operator-bundle",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-ova-provider-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-ova-proxy-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-populator-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-rhv-populator-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-validation-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-virt-v2v-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-vsphere-xcopy-volume-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-agent-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-agent-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-controller-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-controller-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-service-8-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-service-9-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/must-gather-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-agent-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-manager-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-rhel9-operator",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/node-healthcheck-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Affected",
        "package_name": "oadp/oadp-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "helm",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-jenkins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/openshift-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-entrypoint-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-entrypoint-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-events-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-events-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-nop-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-nop-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-resolvers-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-resolvers-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-results-api-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-results-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-results-retention-policy-agent-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-results-retention-policy-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-results-watcher-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-results-watcher-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-sidecarlogresults-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-sidecarlogresults-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-webhook-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-webhook-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-workingdirinit-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-workingdirinit-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/serverless-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-cni-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-pilot-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-sail-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh-tech-preview/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Power monitoring for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-power-monitoring/power-monitoring-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_power_monitoring"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-grafana-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multicloud-integrations-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multiclusterhub-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multicluster-operators-channel-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multicluster-operators-subscription-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/observatorium-rhel9-operator",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/submariner-operator-bundle",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/submariner-rhel9-operator",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Affected",
        "package_name": "advanced-cluster-security/rhacs-central-db-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Affected",
        "package_name": "advanced-cluster-security/rhacs-collector-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Affected",
        "package_name": "advanced-cluster-security/rhacs-main-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Affected",
        "package_name": "advanced-cluster-security/rhacs-operator-bundle",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Affected",
        "package_name": "advanced-cluster-security/rhacs-rhel8-operator",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Affected",
        "package_name": "advanced-cluster-security/rhacs-roxctl-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Affected",
        "package_name": "advanced-cluster-security/rhacs-scanner-v4-db-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Affected",
        "package_name": "advanced-cluster-security/rhacs-scanner-v4-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/aap-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Build of Kueue",
        "fix_state": "Affected",
        "package_name": "kueue/kueue-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:kueue_operator:1"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Affected",
        "package_name": "rhceph/rhceph-promtail-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Certification Program for Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "rhcertification/redhat-certification-baremetal",
        "cpe": "cpe:/a:redhat:certifications:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "container-tools:rhel8/buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "container-tools:rhel8/conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "container-tools:rhel8/podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "container-tools:rhel8/skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Affected",
        "package_name": "rhelai1/bootc-gcp-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-launcher-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-launcher-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "conmon",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "cri-o",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "microshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/cnf-tests-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/cnf-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/container-networking-plugins-microshift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/kube-compare-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/lifecycle-agent-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/metallb-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/metallb-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/microshift-bootc-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/network-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/numaresources-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/numaresources-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/numaresources-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/oc-mirror-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/oc-mirror-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-csr-approver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-csr-approver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-node-agent-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-node-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-orchestrator-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-orchestrator-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-aws-ebs-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-aws-ebs-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-azure-disk-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-azure-disk-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-azure-file-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-azure-file-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-baremetal-installer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-cli",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cli-artifacts",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cli-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-autoscaler-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-console",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-console-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-container-networking-plugins-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-driver-manila-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-driver-shared-resource-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-external-provisioner",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-external-provisioner-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-external-provisioner-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-deployer",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-deployer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-docker-builder",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-docker-builder-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-docker-registry",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-docker-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-helm-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-helm-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-hyperkube",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-hyperkube-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-installer-altinfra-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-installer-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-installer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-kube-proxy",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-kube-proxy-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-local-storage-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-machine-api-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-machine-api-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-machine-config-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-node-feature-discovery",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-node-feature-discovery-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-olm-catalogd-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-olm-catalogd-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-olm-operator-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-olm-operator-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-olm-rukpak-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-olm-rukpak-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-openstack-cinder-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-openstack-cloud-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-framework-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-lifecycle-manager",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-lifecycle-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-registry",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-sdk-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-sdk-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ovn-kubernetes-microshift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ovn-kubernetes-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-powervs-block-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-powervs-block-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-secrets-store-csi-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-tests",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-tools-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vmware-vsphere-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-syncer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ptp-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ztp-site-generate-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift-clients",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "podman",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "redhat/redhat-operator-index",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/devspaces-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/devspaces-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/traefik-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/udi-base-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/udi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Affected",
        "package_name": "openshift4-wincw/windows-machine-config-operator-bundle",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Affected",
        "package_name": "openshift4-wincw/windows-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/argocd-agent-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/argocd-extensions-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/argocd-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/argocd-rhel9",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/argo-rollouts-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/console-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/dex-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/gitops-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/gitops-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/gitops-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Affected",
        "package_name": "openshift-gitops-1/must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/multus-dynamic-networks-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/wasp-agent-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/osp-director-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/osp-director-downloader",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/osp-director-operator",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/osp-director-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel9/osp-director-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel9/osp-director-downloader",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel9/osp-director-operator",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel9/osp-director-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso-operators/openstack-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso-operators/openstack-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso-operators/openstack-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso-operators/prometheus-podman-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso-operators/rabbitmq-cluster-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/policy-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Web Terminal",
        "fix_state": "Affected",
        "package_name": "web-terminal/web-terminal-tooling-rhel9",
        "cpe": "cpe:/a:redhat:webterminal:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-64329\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-64329\nhttps://github.com/containerd/containerd/commit/083b53cd6f19b5de7717b0ce92c11bdf95e612df\nhttps://github.com/containerd/containerd/security/advisories/GHSA-m6hq-p25p-ffr2"
    ],
    "name": "CVE-2025-64329",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-06-25T16:52:24Z",
    "bugzilla": {
      "description": "webrick: Ruby WEBrick Request Smuggling Vulnerability",
      "id": "2374895",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2374895"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
      "status": "draft"
    },
    "cwe": "CWE-444",
    "details": [
      "Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions.\nThe specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.",
      "A request smuggling vulnerability has been discovered in the Ruby WEBrick gem. This vulnerability is exploitable when the product is deployed behind a HTTP proxy that fulfills specific conditions."
    ],
    "package_state": [
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel8",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-cni-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-pilot-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-sail-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/zync-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/zync-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Out of support scope",
        "package_name": "ruby:2.5/ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "ruby:3.3/ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "pcs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "ruby:3.3/ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "puppet-agent",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "rubygem-webrick",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite:el8/rubygem-webrick",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-6442\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-6442\nhttps://access.redhat.com/solutions/7139113\nhttps://github.com/ruby/webrick/commit/ee60354bcb84ec33b9245e1d1aa6e1f7e8132101#diff-ad02984d873efb089aa51551bc6b7d307a53e0ba1ac439e91d69c2e58a478864\nhttps://www.zerodayinitiative.com/advisories/ZDI-25-414/"
    ],
    "name": "CVE-2025-6442",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue is fixed by upgrading to the FB4 client or higher."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-65104\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-65104"
    ],
    "name": "CVE-2025-65104",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-04T00:00:00Z",
    "bugzilla": {
      "description": "github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload",
      "id": "2418900",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418900"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-400",
    "details": [
      "A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with \"token too long\" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.",
      "A denial-of-service vulnerability in github.com/sirupsen/logrus occurs when Entry.Writer() processes a single-line payload larger than 64KB with no newline characters. Due to a limitation in Go’s internal bufio.Scanner, the read operation fails with a “token too long” error, causing the underlying writer pipe to close. In affected versions, this leaves the Writer interface unusable and can disrupt logging functionality, potentially degrading application availability."
    ],
    "statement": "This vulnerability is categorized as Moderate because its impact is limited to the logging subsystem and requires a specific, non-default usage pattern to trigger—namely, sending a single unbounded line exceeding 64KB through Entry.Writer(). Most Logrus deployments do not expose this interface directly to attacker-controlled input, which raises the attack complexity and reduces realistic exploitability. Additionally, the flaw does not affect confidentiality or integrity, nor does it allow code execution or privilege escalation. The failure results in a controlled degradation of availability (logging becoming non-functional), rather than a broader application outage or systemic compromise. These constrained conditions and limited real-world impact justify treating the issue as moderate rather than important.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3428",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "container-tools:rhel8-8100020260204142227.afee755d"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10703",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "container-tools:rhel8-8060020260422144418.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2687",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "osbuild-composer-0:46.3-5.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10703",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "container-tools:rhel8-8060020260422144418.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2687",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "osbuild-composer-0:46.3-5.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10703",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "container-tools:rhel8-8060020260422144418.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2687",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "osbuild-composer-0:46.3-5.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-02-12T00:00:00Z",
        "advisory": "RHSA-2026:2685",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "osbuild-composer-0:75-6.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4693",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "container-tools:rhel8-8080020260226135022.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6191",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "container-tools:rhel8-8080020260325222945.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-02-12T00:00:00Z",
        "advisory": "RHSA-2026:2685",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "osbuild-composer-0:75-6.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4693",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "container-tools:rhel8-8080020260226135022.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6191",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "container-tools:rhel8-8080020260325222945.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15940",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "oci-seccomp-bpf-hook-0:1.2.10-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15941",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "skopeo-2:1.8.0-4.1.el9_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-02-12T00:00:00Z",
        "advisory": "RHSA-2026:2686",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "osbuild-composer-0:46.3-6.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8325",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "buildah-1:1.26.9-1.el9_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8325",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "podman-2:4.2.0-6.el9_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8325",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "runc-4:1.2.9-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11804",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "oci-seccomp-bpf-hook-0:1.2.10-1.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13971",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "skopeo-2:1.11.4-0.1.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2519",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "toolbox-0:0.0.99.4.1-1.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2688",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "osbuild-composer-0:76.1-4.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4531",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "runc-4:1.2.9-1.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4532",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "buildah-1:1.29.5-1.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4533",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "podman-2:4.4.1-22.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-12T00:00:00Z",
        "advisory": "RHSA-2026:0425",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "runc-4:1.2.9-1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2520",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "toolbox-0:0.0.99.5.1-2.el9_4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-08T00:00:00Z",
        "advisory": "RHSA-2026:12273",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "openshift-0:4.12.0-202604271501.p2.gedc7ba9.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7238",
        "cpe": "cpe:/a:redhat:openshift:4.13::el8",
        "package": "openshift-0:4.13.0-202603240119.p2.g7aa9360.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2973",
        "cpe": "cpe:/a:redhat:openshift:4.14::el8",
        "package": "openshift-0:4.14.0-202602170118.p2.ga3faddd.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1540",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "kernel-0:5.14.0-284.155.1.el9_2"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1540",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "kernel-rt-0:5.14.0-284.155.1.rt14.440.el9_2"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1540",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "python-eventlet-0:0.33.1-7.el9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1540",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "runc-4:1.2.9-1.rhaos4.16.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4418",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "openshift-0:4.15.0-202602130120.p2.g5cb2ef4.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1540",
        "cpe": "cpe:/a:redhat:openshift_ironic:4.15::el9",
        "package": "kernel-0:5.14.0-284.155.1.el9_2"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1540",
        "cpe": "cpe:/a:redhat:openshift_ironic:4.15::el9",
        "package": "kernel-rt-0:5.14.0-284.155.1.rt14.440.el9_2"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1540",
        "cpe": "cpe:/a:redhat:openshift_ironic:4.15::el9",
        "package": "python-eventlet-0:0.33.1-7.el9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1540",
        "cpe": "cpe:/a:redhat:openshift_ironic:4.15::el9",
        "package": "runc-4:1.2.9-1.rhaos4.16.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2658",
        "cpe": "cpe:/a:redhat:openshift:4.16::el8",
        "package": "openshift-0:4.16.0-202602100409.p2.g41c4e9b.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4580",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "microshift-0:4.16.58-202603160404.p0.gb9661ec.assembly.4.16.58.el9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2670",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "openshift-0:4.17.0-202602031716.p2.g4e295fa.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2746",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "microshift-0:4.17.49-202602161401.p0.g708a69a.assembly.4.17.49.el9"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18.0",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:7885",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "golang-github-openstack-k8s-operators-os-diff-0:0.1.1-18.0.20260225161428.32d52e7.el9ost"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2351",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/volsync-rhel9:1770249158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3099",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "openshift4/topology-aware-lifecycle-manager-rhel8-operator:1771322552"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6911",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "openshift4/ztp-site-generate-rhel8:1775531925"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-hyperkube:1777304752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-02-12T00:00:00Z",
        "advisory": "RHSA-2026:2065",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1770041992"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-02-12T00:00:00Z",
        "advisory": "RHSA-2026:2065",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1770042014"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-02-12T00:00:00Z",
        "advisory": "RHSA-2026:2065",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel8:1770041173"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-02-12T00:00:00Z",
        "advisory": "RHSA-2026:2065",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1770040836"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-02-12T00:00:00Z",
        "advisory": "RHSA-2026:2066",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-local-storage-operator:1770040667"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3870",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1772199796"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3870",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1772199883"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3870",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1772199823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3870",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-storage-operator:1772199876"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3870",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1772199865"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3870",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1772199848"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3870",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1772199839"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3870",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1772200204"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3870",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1772200198"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3870",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1772199782"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3870",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1772199863"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3871",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/cloud-event-proxy-rhel8:1772587579"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3871",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ptp:1772199893"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3871",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ptp-operator:1772587554"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3871",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ptp-must-gather-rhel8:1772201700"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6493",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1774273670"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6493",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1774273704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6493",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1774273672"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6493",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1774273561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6493",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1774661147"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6493",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus:1774273251"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6493",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-thanos-rhel8:1774273613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3422",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel8:1771854172"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3422",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1771854059"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3422",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1771854305"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3422",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-storage-operator:1771854291"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3422",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1771854082"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3422",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1771854233"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3422",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-operator:1771854000"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3422",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1771854054"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3422",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus:1771853704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3422",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-thanos-rhel8:1771854283"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3422",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1771854404"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3422",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1771854170"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3422",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1771854066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3423",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-local-storage-rhel9-operator:1771854031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3423",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ptp:1771854209"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3423",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ptp-operator:1771853987"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3423",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ptp-must-gather-rhel8:1771855696"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7252",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1775613995"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7252",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1775614176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7252",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1775614042"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7252",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1775614020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7252",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1775614011"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7252",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-hyperkube:1775613982"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7252",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1775614035"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7252",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1775614004"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7252",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1775614027"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7252",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1775614068"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7253",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cloud-event-proxy:1775613976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7253",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cloud-event-proxy-rhel8:1775613976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-01-30T00:00:00Z",
        "advisory": "RHSA-2026:1004",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-local-storage-operator:1769004053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2990",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1770905009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2990",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1770734979"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2990",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1771369118"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2990",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-storage-operator:1770743637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2990",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1771294265"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2990",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1771369290"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2990",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1771369120"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2990",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-thanos-rhel8:1771294312"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2990",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1770735085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2990",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1770735124"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2990",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1770734951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2990",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1770991275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2991",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-rhel8-operator:1770817346"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2991",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-filestore-csi-driver-rhel8:1771369531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2991",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ptp-operator:1771369170"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2991",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ptp-rhel9:1771369177"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2991",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ptp-must-gather-rhel8:1770753255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1773344342"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1773368919"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1773342046"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1773342109"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1773338018"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1773335690"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-operator:1773343031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1773345444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5107",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1773338014"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5108",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/cloud-event-proxy-rhel8:1773339545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5108",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cloud-event-proxy-rhel8:1773339545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1777478065"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1777519369"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1549",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel9:1769535823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1549",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1769535080"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1549",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1769093424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1549",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1769541325"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1549",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1769093428"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1549",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1769093450"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1549",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1769535462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1549",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1769094106"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772166357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772459252"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772159291"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772501601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1772593677"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772159941"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1772593433"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772158357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772718295"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1772593880"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1772593753"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1772591634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772158737"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1772591634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4423",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1772158737"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4424",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-rhel8-operator:1772762684"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4424",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cloud-event-proxy-rhel9:1772158249"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4424",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-filestore-csi-driver-rhel8:1772795521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4424",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-filestore-csi-driver-rhel8-operator:1772795472"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4424",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ptp-rhel9:1772158936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4424",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ptp-rhel9-operator:1772589956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4424",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ptp-must-gather-rhel8:1772598327"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0327",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1766066934"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2661",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1770699844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2661",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1770662075"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2662",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-filestore-csi-driver-rhel9:1770665823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2662",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ptp-rhel9-operator:1770664468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2662",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ptp-must-gather-rhel9:1770685682"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772202555"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772201713"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772201467"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772589085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772204306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772286010"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772201612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772202943"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772545401"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1773108630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4482",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772202424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4483",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cloud-event-proxy-rhel9:1772203748"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4483",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ptp-rhel9:1772201507"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0715",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1768303721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0715",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1768357184"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1577",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1769618624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1577",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1769596613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1778709453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2672",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1770654820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2672",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1770639680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2672",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1770646496"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2672",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1770653353"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2672",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1770638256"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2672",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1770632411"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2672",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1770660400"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2673",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-filestore-csi-driver-rhel9:1770636671"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2673",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ptp-rhel9-operator:1770637118"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2673",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ptp-must-gather-rhel9:1770657389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3418",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1771990491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3418",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1771990438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3418",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1771991141"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3418",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1771990122"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3418",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1771990055"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3418",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1771989226"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3418",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1771989671"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3418",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1771992100"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3419",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cloud-event-proxy-rhel9:1771988611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3419",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ptp-rhel9:1771988801"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772152073"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772148644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772194956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772864906"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:4510",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772148709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:5907",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1774320480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-01-14T00:00:00Z",
        "advisory": "RHSA-2026:0338",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1766054508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-02-03T00:00:00Z",
        "advisory": "RHSA-2026:1062",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1768936257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2078",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1770177353"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2078",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1769825791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2078",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1770020259"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2079",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-filestore-csi-driver-rhel9:1769819530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:2977",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1771029693"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:2977",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1771035154"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:2977",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1771030944"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:2977",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1771034229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:2978",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cloud-event-proxy-rhel9:1771033423"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5133",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772732196"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1552",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1769418091"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1552",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1768606951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2651",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1770685815"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2651",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1770661976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2651",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1770665899"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2652",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cloud-event-proxy-rhel9:1770663123"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2652",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-filestore-csi-driver-rhel9:1770662081"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4434",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772167583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1555",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1769557482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1556",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-filestore-csi-driver-rhel9:1769553296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2119",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1770171985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2120",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cloud-event-proxy-rhel9:1770083975"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772142447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772574868"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2129",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1770081958"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2130",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-cloud-event-proxy-rhel9:1769819514"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2130",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-gcp-filestore-csi-driver-rhel9:1769725944"
      }
    ],
    "package_state": [
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Not affected",
        "package_name": "assisted/agent-preinstall-image-builder-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Not affected",
        "package_name": "rhai/assisted-installer-agent-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Not affected",
        "package_name": "rhai/assisted-installer-controller-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Not affected",
        "package_name": "rhai/assisted-installer-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Builds for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-builds/openshift-builds-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_builds:1"
      },
      {
        "product_name": "Builds for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-builds/openshift-builds-git-cloner-rhel9",
        "cpe": "cpe:/a:redhat:openshift_builds:1"
      },
      {
        "product_name": "Builds for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-builds/openshift-builds-image-bundler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_builds:1"
      },
      {
        "product_name": "Builds for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-builds/openshift-builds-image-processing-rhel9",
        "cpe": "cpe:/a:redhat:openshift_builds:1"
      },
      {
        "product_name": "Builds for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-builds/openshift-builds-waiters-rhel9",
        "cpe": "cpe:/a:redhat:openshift_builds:1"
      },
      {
        "product_name": "Builds for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-builds/openshift-builds-webhook-rhel9",
        "cpe": "cpe:/a:redhat:openshift_builds:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "cert-manager/cert-manager-istio-csr-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "cert-manager/cert-manager-operator-bundle",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "cert-manager/cert-manager-operator-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "cert-manager/jetstack-cert-manager-acmesolver-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "cert-manager/jetstack-cert-manager-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "Compliance Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-compliance-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1"
      },
      {
        "product_name": "Compliance Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-compliance-openscap-rhel8",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1"
      },
      {
        "product_name": "Compliance Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-compliance-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1"
      },
      {
        "product_name": "Compliance Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-compliance-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Out of support scope",
        "package_name": "openshift-sandboxed-containers/osc-monitor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Out of support scope",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Out of support scope",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Out of support scope",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Out of support scope",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Cost Management Metrics Operator",
        "fix_state": "Not affected",
        "package_name": "costmanagement/costmanagement-metrics-operator-bundle",
        "cpe": "cpe:/a:redhat:cost_management:1"
      },
      {
        "product_name": "Cost Management Metrics Operator",
        "fix_state": "Not affected",
        "package_name": "costmanagement/costmanagement-metrics-rhel9-operator",
        "cpe": "cpe:/a:redhat:cost_management:1"
      },
      {
        "product_name": "Cost Management Metrics Operator",
        "fix_state": "Not affected",
        "package_name": "costmanagement/costmanagement-metrics-operator-bundle",
        "cpe": "cpe:/a:redhat:cost_management:4"
      },
      {
        "product_name": "Cost Management Metrics Operator",
        "fix_state": "Not affected",
        "package_name": "costmanagement/costmanagement-metrics-rhel9-operator",
        "cpe": "cpe:/a:redhat:cost_management:4"
      },
      {
        "product_name": "Cryostat 4",
        "fix_state": "Not affected",
        "package_name": "cryostat/cryostat-rhel9-operator",
        "cpe": "cpe:/a:redhat:cryostat:4"
      },
      {
        "product_name": "Cryostat 4",
        "fix_state": "Not affected",
        "package_name": "cryostat/cryostat-storage-rhel9",
        "cpe": "cpe:/a:redhat:cryostat:4"
      },
      {
        "product_name": "Custom Metric Autoscaler operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
      },
      {
        "product_name": "Custom Metric Autoscaler operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
      },
      {
        "product_name": "Custom Metric Autoscaler operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "custom-metrics-autoscaler/custom-metrics-autoscaler-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
      },
      {
        "product_name": "Custom Metric Autoscaler operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
      },
      {
        "product_name": "Custom Metric Autoscaler operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
      },
      {
        "product_name": "Deployment Validation Operator",
        "fix_state": "Not affected",
        "package_name": "dvo/deployment-validation-rhel8-operator",
        "cpe": "cpe:/a:redhat:deployment_validator_operator"
      },
      {
        "product_name": "Dynamic Accelerator Slicer Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "dynamic-accelerator-slicer-tech-preview/instaslice-daemonset-rhel9",
        "cpe": "cpe:/a:redhat:dynamic_accelerator_slicer:1"
      },
      {
        "product_name": "Dynamic Accelerator Slicer Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "dynamic-accelerator-slicer-tech-preview/instaslice-operator-bundle",
        "cpe": "cpe:/a:redhat:dynamic_accelerator_slicer:1"
      },
      {
        "product_name": "Dynamic Accelerator Slicer Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "dynamic-accelerator-slicer-tech-preview/instaslice-rhel9-operator",
        "cpe": "cpe:/a:redhat:dynamic_accelerator_slicer:1"
      },
      {
        "product_name": "Dynamic Accelerator Slicer Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "dynamic-accelerator-slicer-tech-preview/instaslice-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:dynamic_accelerator_slicer:1"
      },
      {
        "product_name": "Dynamic Accelerator Slicer Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "dynamic-accelerator-slicer-tech-preview/instaslice-webhook-rhel9",
        "cpe": "cpe:/a:redhat:dynamic_accelerator_slicer:1"
      },
      {
        "product_name": "ExternalDNS Operator",
        "fix_state": "Out of support scope",
        "package_name": "edo/external-dns-rhel8",
        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
      },
      {
        "product_name": "ExternalDNS Operator",
        "fix_state": "Out of support scope",
        "package_name": "edo/external-dns-rhel9",
        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/bitwarden-sdk-server-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-operator-bundle",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-operator-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "external secrets operator for Red Hat OpenShift - Tech Preview",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/bitwarden-sdk-server-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:0"
      },
      {
        "product_name": "external secrets operator for Red Hat OpenShift - Tech Preview",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-operator-bundle",
        "cpe": "cpe:/a:redhat:external_secrets_operator:0"
      },
      {
        "product_name": "external secrets operator for Red Hat OpenShift - Tech Preview",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-operator-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:0"
      },
      {
        "product_name": "external secrets operator for Red Hat OpenShift - Tech Preview",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:0"
      },
      {
        "product_name": "File Integrity Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-compliance-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1"
      },
      {
        "product_name": "File Integrity Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-compliance-openscap-rhel8",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1"
      },
      {
        "product_name": "File Integrity Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-compliance-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1"
      },
      {
        "product_name": "File Integrity Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-compliance-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1"
      },
      {
        "product_name": "File Integrity Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-file-integrity-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1"
      },
      {
        "product_name": "File Integrity Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-file-integrity-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1"
      },
      {
        "product_name": "Gatekeeper 3",
        "fix_state": "Not affected",
        "package_name": "gatekeeper/gatekeeper-rhel9",
        "cpe": "cpe:/a:redhat:gatekeeper:3"
      },
      {
        "product_name": "Job Set Tech Preview",
        "fix_state": "Not affected",
        "package_name": "job-set/jobset-operator-bundle",
        "cpe": "cpe:/a:redhat:job_set:0"
      },
      {
        "product_name": "Job Set Tech Preview",
        "fix_state": "Not affected",
        "package_name": "job-set/jobset-rhel9-operator",
        "cpe": "cpe:/a:redhat:job_set:0"
      },
      {
        "product_name": "Kernel Module Management Operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "kmm/kernel-module-management-hub-operator-bundle",
        "cpe": "cpe:/a:redhat:kernel_module_management:2"
      },
      {
        "product_name": "Kernel Module Management Operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "kmm/kernel-module-management-hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:kernel_module_management:2"
      },
      {
        "product_name": "Kernel Module Management Operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "kmm/kernel-module-management-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:kernel_module_management:2"
      },
      {
        "product_name": "Kernel Module Management Operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "kmm/kernel-module-management-operator-bundle",
        "cpe": "cpe:/a:redhat:kernel_module_management:2"
      },
      {
        "product_name": "Kernel Module Management Operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "kmm/kernel-module-management-rhel9-operator",
        "cpe": "cpe:/a:redhat:kernel_module_management:2"
      },
      {
        "product_name": "Kernel Module Management Operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "kmm/kernel-module-management-signing-rhel9",
        "cpe": "cpe:/a:redhat:kernel_module_management:2"
      },
      {
        "product_name": "Kernel Module Management Operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "kmm/kernel-module-management-webhook-server-rhel9",
        "cpe": "cpe:/a:redhat:kernel_module_management:2"
      },
      {
        "product_name": "Kernel Module Management Operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "kmm/kernel-module-management-worker-rhel9",
        "cpe": "cpe:/a:redhat:kernel_module_management:2"
      },
      {
        "product_name": "Kube Descheduler Operator",
        "fix_state": "Affected",
        "package_name": "kube-descheduler-operator/kube-descheduler-operator-bundle",
        "cpe": "cpe:/a:redhat:kube_descheduler_operator:4"
      },
      {
        "product_name": "Kube Descheduler Operator",
        "fix_state": "Affected",
        "package_name": "kube-descheduler-operator/kube-descheduler-rhel9-operator",
        "cpe": "cpe:/a:redhat:kube_descheduler_operator:4"
      },
      {
        "product_name": "Kube Descheduler Operator",
        "fix_state": "Not affected",
        "package_name": "kube-descheduler-operator/kube-descheduler-operator-bundle",
        "cpe": "cpe:/a:redhat:kube_descheduler_operator:5"
      },
      {
        "product_name": "Kube Descheduler Operator",
        "fix_state": "Out of support scope",
        "package_name": "kube-descheduler-operator/kube-descheduler-rhel9-operator",
        "cpe": "cpe:/a:redhat:kube_descheduler_operator:5"
      },
      {
        "product_name": "Leader Worker Set",
        "fix_state": "Not affected",
        "package_name": "leader-worker-set/lws-operator-bundle",
        "cpe": "cpe:/a:redhat:leader_worker_set:1"
      },
      {
        "product_name": "Leader Worker Set",
        "fix_state": "Not affected",
        "package_name": "leader-worker-set/lws-rhel9-operator",
        "cpe": "cpe:/a:redhat:leader_worker_set:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/elasticsearch6-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/elasticsearch-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/elasticsearch-proxy-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/elasticsearch-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/kibana6-rhel8",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/logging-curator5-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/loki-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/loki-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/lokistack-gateway-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/opa-openshift-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/loki-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/loki-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/lokistack-gateway-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/opa-openshift-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Out of support scope",
        "package_name": "lvms4/lvms-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Out of support scope",
        "package_name": "lvms4/lvms-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Not affected",
        "package_name": "lvms4/lvms-operator-bundle",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Out of support scope",
        "package_name": "lvms4/lvms-rhel9-operator",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/machine-deletion-remediation-operator-bundle",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/machine-deletion-remediation-rhel9-operator",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "Migration Toolkit for Applications 7",
        "fix_state": "Not affected",
        "package_name": "mta/mta-analyzer-addon-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
      },
      {
        "product_name": "Migration Toolkit for Applications 7",
        "fix_state": "Not affected",
        "package_name": "mta/mta-cli-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
      },
      {
        "product_name": "Migration Toolkit for Applications 7",
        "fix_state": "Not affected",
        "package_name": "mta/mta-discovery-addon-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
      },
      {
        "product_name": "Migration Toolkit for Applications 7",
        "fix_state": "Not affected",
        "package_name": "mta/mta-dotnet-external-provider-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
      },
      {
        "product_name": "Migration Toolkit for Applications 7",
        "fix_state": "Not affected",
        "package_name": "mta/mta-dotnet-external-provider-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
      },
      {
        "product_name": "Migration Toolkit for Applications 7",
        "fix_state": "Affected",
        "package_name": "mta/mta-generic-external-provider-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
      },
      {
        "product_name": "Migration Toolkit for Applications 7",
        "fix_state": "Not affected",
        "package_name": "mta/mta-hub-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
      },
      {
        "product_name": "Migration Toolkit for Applications 7",
        "fix_state": "Affected",
        "package_name": "mta/mta-java-external-provider-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:7"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-analyzer-addon-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-cli-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-discovery-addon-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-dotnet-external-provider-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-dotnet-external-provider-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-generic-external-provider-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-hub-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-java-external-provider-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-platform-addon-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-controller-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-hook-runner-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Not affected",
        "package_name": "rhmtc/openshift-migration-log-reader-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Not affected",
        "package_name": "rhmtc/openshift-migration-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Not affected",
        "package_name": "rhmtc/openshift-migration-registry-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Not affected",
        "package_name": "rhmtc/openshift-migration-rhel8-operator",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-velero-plugin-for-mtc-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-api-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-cli-download-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-openstack-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-operator-bundle",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-ova-provider-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-ova-proxy-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-populator-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-rhv-populator-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-validation-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-virt-v2v-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-vsphere-xcopy-volume-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-api-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-cli-download-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-openstack-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-operator-bundle",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-ova-provider-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-ova-proxy-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-populator-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-rhv-populator-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-validation-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-virt-v2v-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-vsphere-xcopy-volume-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "mirror registry for Red Hat OpenShift",
        "fix_state": "Will not fix",
        "package_name": "openshift/mirror-registry-rhel8",
        "cpe": "cpe:/a:redhat:mirror_registry:1"
      },
      {
        "product_name": "mirror registry for Red Hat OpenShift 2",
        "fix_state": "Affected",
        "package_name": "openshift/mirror-registry-rhel8",
        "cpe": "cpe:/a:redhat:mirror_registry:2"
      },
      {
        "product_name": "Multiarch Tuning Operator",
        "fix_state": "Not affected",
        "package_name": "multiarch-tuning/multiarch-tuning-operator-bundle",
        "cpe": "cpe:/a:redhat:multiarch_tuning_operator"
      },
      {
        "product_name": "Multiarch Tuning Operator",
        "fix_state": "Not affected",
        "package_name": "multiarch-tuning/multiarch-tuning-rhel9-operator",
        "cpe": "cpe:/a:redhat:multiarch_tuning_operator"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/addon-manager-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/addon-manager-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-image-service-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-image-service-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-installer-agent-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-installer-agent-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-installer-controller-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-installer-controller-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-installer-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-installer-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-service-8-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-service-9-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine-capoa-bootstrap-container",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/capoa-bootstrap-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine-capoa-control-plane-container",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/capoa-control-plane-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/cluster-api-provider-agent-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/cluster-api-provider-agent-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/hive-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/hive-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/hypershift-addon-rhel8-operator",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/hypershift-addon-rhel9-operator",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/hypershift-cli-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/hypershift-cli-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/hypershift-rhel8-operator",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/hypershift-rhel9-operator",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/image-based-install-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/must-gather-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/must-gather-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/placement-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/placement-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/registration-operator-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/registration-operator-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/registration-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/registration-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/work-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/work-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Not affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-agent-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Not affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Not affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-manager-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Not affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-operator-bundle",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Not affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-rhel9-operator",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Not affected",
        "package_name": "network-observability/network-observability-cli-rhel9",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Not affected",
        "package_name": "network-observability/network-observability-console-plugin-compat-rhel9",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Not affected",
        "package_name": "network-observability/network-observability-console-plugin-rhel9",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Not affected",
        "package_name": "network-observability/network-observability-ebpf-agent-rhel9",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Not affected",
        "package_name": "network-observability/network-observability-flowlogs-pipeline-rhel9",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Not affected",
        "package_name": "network-observability/network-observability-operator-bundle",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Not affected",
        "package_name": "network-observability/network-observability-rhel9-operator",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Out of support scope",
        "package_name": "workload-availability/node-healthcheck-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Out of support scope",
        "package_name": "workload-availability/node-healthcheck-operator-bundle",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Out of support scope",
        "package_name": "workload-availability/node-healthcheck-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Out of support scope",
        "package_name": "workload-availability/node-healthcheck-rhel9-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Out of support scope",
        "package_name": "workload-availability/node-remediation-console-rhel9",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "Node Maintenance Operator",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/node-maintenance-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nmo:5"
      },
      {
        "product_name": "Node Maintenance Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/node-maintenance-operator-bundle",
        "cpe": "cpe:/a:redhat:workload_availability_nmo:5"
      },
      {
        "product_name": "Node Maintenance Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/node-maintenance-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nmo:5"
      },
      {
        "product_name": "Node Maintenance Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/node-maintenance-rhel9-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nmo:5"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Not affected",
        "package_name": "oadp/oadp-hypershift-velero-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-kubevirt-velero-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-kubevirt-velero-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-mustgather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Not affected",
        "package_name": "oadp/oadp-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Not affected",
        "package_name": "oadp/oadp-non-admin-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-velero-plugin-for-aws-rhel8",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-velero-plugin-for-aws-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-velero-plugin-for-csi-rhel8",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-velero-plugin-for-csi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-velero-plugin-for-gcp-rhel8",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-velero-plugin-for-gcp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-velero-plugin-for-legacy-aws-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-velero-plugin-for-microsoft-azure-rhel8",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-velero-plugin-for-microsoft-azure-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Not affected",
        "package_name": "oadp/oadp-velero-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Not affected",
        "package_name": "oadp/oadp-velero-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-velero-restic-restore-helper-rhel8",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-velero-restic-restore-helper-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Out of support scope",
        "package_name": "oadp/oadp-velero-rhel8",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Not affected",
        "package_name": "oadp/oadp-velero-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Out of support scope",
        "package_name": "helm",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "ocp-tools-4/jenkins-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-jenkins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/openshift-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines-client",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-cache-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-chains-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-chains-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-cli-tkn-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-cli-tkn-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-entrypoint-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-entrypoint-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-events-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-events-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-hub-api-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-hub-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-hub-db-migration-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-hub-db-migration-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-hub-ui-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-hub-ui-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-manual-approval-gate-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-manual-approval-gate-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-manual-approval-gate-webhook-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-manual-approval-gate-webhook-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-nop-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-nop-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-opc-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-operator-proxy-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-operator-proxy-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-operator-webhook-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-operator-webhook-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-pruner-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-resolvers-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-resolvers-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-results-api-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-results-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-results-retention-policy-agent-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-results-retention-policy-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-results-watcher-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-results-watcher-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-sidecarlogresults-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-sidecarlogresults-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Out of support scope",
        "package_name": "openshift-pipelines/pipelines-triggers-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Out of support scope",
        "package_name": "openshift-pipelines/pipelines-triggers-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Out of support scope",
        "package_name": "openshift-pipelines/pipelines-triggers-core-interceptors-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Out of support scope",
        "package_name": "openshift-pipelines/pipelines-triggers-core-interceptors-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Out of support scope",
        "package_name": "openshift-pipelines/pipelines-triggers-eventlistenersink-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Out of support scope",
        "package_name": "openshift-pipelines/pipelines-triggers-eventlistenersink-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Out of support scope",
        "package_name": "openshift-pipelines/pipelines-triggers-webhook-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Out of support scope",
        "package_name": "openshift-pipelines/pipelines-triggers-webhook-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-webhook-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-webhook-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-workingdirinit-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-workingdirinit-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Secondary Scheduler Operator",
        "fix_state": "Out of support scope",
        "package_name": "openshift-secondary-scheduler-operator/secondary-scheduler-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_secondary_scheduler:1"
      },
      {
        "product_name": "OpenShift Secondary Scheduler Operator",
        "fix_state": "Out of support scope",
        "package_name": "openshift-secondary-scheduler-operator/secondary-scheduler-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_secondary_scheduler:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Not affected",
        "package_name": "openshift-serverless-1/kn-client-kn-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Not affected",
        "package_name": "openshift-serverless-1/kn-plugin-event-sender-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Not affected",
        "package_name": "openshift-serverless-1/kn-plugin-func-func-util-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Not affected",
        "package_name": "openshift-serverless-1/kn-serving-controller-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Not affected",
        "package_name": "openshift-serverless-1/serverless-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Not affected",
        "package_name": "openshift-serverless-clients",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Out of support scope",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-cni-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-pilot-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-sail-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh-tech-preview/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Source-to-Image (S2I)",
        "fix_state": "Not affected",
        "package_name": "source-to-image/source-to-image-rhel8",
        "cpe": "cpe:/a:redhat:source_to_image:1"
      },
      {
        "product_name": "Power monitoring for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-power-monitoring/power-monitoring-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_power_monitoring"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Affected",
        "package_name": "3scale-amp2/3scale-operator-bundle",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp2/3scale-rhel7-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Affected",
        "package_name": "3scale-amp2/3scale-rhel9-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp26/3scale-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp26/operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-tech-preview/authorino-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "rhcl-1/authorino-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "flightctl",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-cli-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-flightctl-api-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-flightctl-ocp-ui-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-flightctl-periodic-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-flightctl-ui-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-flightctl-worker-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-governance-policy-addon-controller-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Out of support scope",
        "package_name": "rhacm2/acm-grafana-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-multicluster-observability-addon-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-prometheus-config-reloader-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-prometheus-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-volsync-addon-controller-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Out of support scope",
        "package_name": "rhacm2/config-policy-controller-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/multicloud-integrations-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/multiclusterhub-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/multicluster-operators-channel-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multicluster-operators-subscription-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/nettest-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/observatorium-rhel9-operator",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/prometheus-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/submariner-addon-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/submariner-operator-bundle",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/submariner-rhel9-operator",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/thanos-receive-controller-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/thanos-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/volsync-operator-bundle",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-central-db-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-collector-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-main-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-operator-bundle",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-rhel8-operator",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-roxctl-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-scanner-db-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-scanner-db-slim-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-scanner-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-scanner-slim-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-scanner-v4-db-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-scanner-v4-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhai/base-image-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhai/base-image-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhai/base-image-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/aap-cloud-ui-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/aap-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/receptor-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform/platform-operator-bundle",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "flightctl",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "receptor",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Build of Kueue",
        "fix_state": "Not affected",
        "package_name": "kueue/kueue-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:kueue_operator:1"
      },
      {
        "product_name": "Red Hat Build of Kueue",
        "fix_state": "Not affected",
        "package_name": "kueue/kueue-operator-bundle",
        "cpe": "cpe:/a:redhat:kueue_operator:1"
      },
      {
        "product_name": "Red Hat Build of Kueue",
        "fix_state": "Not affected",
        "package_name": "kueue/kueue-rhel9",
        "cpe": "cpe:/a:redhat:kueue_operator:1"
      },
      {
        "product_name": "Red Hat Build of Kueue",
        "fix_state": "Not affected",
        "package_name": "kueue/kueue-rhel9-operator",
        "cpe": "cpe:/a:redhat:kueue_operator:1"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Not affected",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Not affected",
        "package_name": "rhceph/snmp-notifier-rhel8",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Not affected",
        "package_name": "rhceph/snmp-notifier-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Not affected",
        "package_name": "rhel8/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Not affected",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Not affected",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Not affected",
        "package_name": "rhceph/snmp-notifier-rhel8",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Not affected",
        "package_name": "rhceph/snmp-notifier-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Not affected",
        "package_name": "rhel8/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Not affected",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Not affected",
        "package_name": "rhceph/snmp-notifier-rhel8",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Not affected",
        "package_name": "rhceph/snmp-notifier-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Not affected",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Not affected",
        "package_name": "rhceph/rhceph-promtail-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Not affected",
        "package_name": "rhceph/snmp-notifier-rhel8",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Not affected",
        "package_name": "rhceph/snmp-notifier-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Not affected",
        "package_name": "rhel8/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Not affected",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Certification Program for Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "redhat-certification-preflight",
        "cpe": "cpe:/a:redhat:certifications:9"
      },
      {
        "product_name": "Red Hat Certification Program for Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhcertification/redhat-certification-baremetal",
        "cpe": "cpe:/a:redhat:certifications:9"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Not affected",
        "package_name": "3scale-tech-preview/authorino-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Not affected",
        "package_name": "rhcl-1/authorino-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Not affected",
        "package_name": "rhcl-1/coredns-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Not affected",
        "package_name": "rhcl-1/dns-operator-bundle",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Not affected",
        "package_name": "rhcl-1/dns-rhel9-operator",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Not affected",
        "package_name": "rhcl-1/rhcl-operator-bundle",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Not affected",
        "package_name": "rhcl-1/rhcl-rhel9-operator",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Not affected",
        "package_name": "rhcl-beta/dns-operator-bundle",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Not affected",
        "package_name": "rhcl-beta/dns-rhel9-operator",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Not affected",
        "package_name": "rhdh/rhdh-hub-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "flightctl",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-flightctl-api-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-flightctl-ocp-ui-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-flightctl-periodic-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-flightctl-ui-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-flightctl-worker-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhem/flightctl-alert-exporter-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhem/flightctl-alertmanager-proxy-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhem/flightctl-api-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhem/flightctl-cli-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhem/flightctl-db-setup-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhem/flightctl-periodic-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhem/flightctl-telemetry-gateway-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhem/flightctl-ui-ocp-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhem/flightctl-ui-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhem/flightctl-userinfo-proxy-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Edge Manager preview",
        "fix_state": "Not affected",
        "package_name": "rhem/flightctl-worker-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "gvisor-tap-vsock",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "oci-seccomp-bpf-hook",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "osbuild-composer",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rhel10/bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rhel10/buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rhel10-eus/rhel-10.0-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rhel10-eus/rhel-10.0-bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rhel10/grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rhel10/podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rhel10/rhel-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rhel10/skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "ubi10/buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "ubi10/podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "ubi10/skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "host-metering",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "osbuild-composer",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "rhel8/grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "gvisor-tap-vsock",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "oci-seccomp-bpf-hook",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "osbuild-composer",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9/bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9/buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9-eus/rhel-9.6-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9-eus/rhel-9.6-bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9/rhel-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9/skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "runc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "ubi9/buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "ubi9/skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-aws-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-azure-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-gcp-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Not affected",
        "package_name": "rhelai1/bootc-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-codeflare-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-codeflare-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-argoexec-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-argoexec-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Out of support scope",
        "package_name": "rhoai/odh-data-science-pipelines-operator-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-data-science-pipelines-operator-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Out of support scope",
        "package_name": "rhoai/odh-kf-notebook-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Out of support scope",
        "package_name": "rhoai/odh-kueue-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kueue-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-launcher-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-launcher-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-mod-arch-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-metadata-collection-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Out of support scope",
        "package_name": "rhoai/odh-notebook-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Out of support scope",
        "package_name": "rhoai/odh-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Out of support scope",
        "package_name": "rhoai/odh-training-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Cluster Manager CLI",
        "fix_state": "Not affected",
        "package_name": "ocm-cli-clients/ocm-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_cluster_manager_cli:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-compliance-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-compliance-openscap-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-compliance-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "conmon-rs",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "cri-o",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "cri-tools",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/azure-kms-encryption-provider-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/cnf-tests-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/cnf-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/frr-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/kube-compare-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/kubevirt-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/lifecycle-agent-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/lifecycle-agent-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/metallb-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/metallb-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/metallb-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/microshift-bootc-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/network-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/noderesourcetopology-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/numaresources-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/oc-mirror-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/oc-mirror-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/openshift-route-controller-manager-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/openshift-route-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-csr-approver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-node-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-orchestrator-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-orchestrator-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-ui-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-utils-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-aws-cluster-api-controllers-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-aws-cluster-api-controllers-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-aws-ebs-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-aws-ebs-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-aws-efs-csi-driver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-disk-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-azure-disk-csi-driver-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-disk-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-azure-disk-csi-driver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-azure-file-csi-driver-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-file-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-file-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-baremetal-installer-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-baremetal-runtimecfg-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-baremetal-runtimecfg-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli-artifacts",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cloud-credential-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cloud-credential-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cloud-event-proxy-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-authentication-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-baremetal-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-capacity-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-capi-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-config-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-config-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-dns-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-dns-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-ingress-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-ingress-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-kube-controller-manager-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-network-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-network-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-node-tuning-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-node-tuning-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-olm-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-olm-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-openshift-apiserver-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-platform-operators-manager-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-platform-operators-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-policy-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cluster-policy-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-samples-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-samples-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-version-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-version-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-console",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-console-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-console-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-container-networking-plugins-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-contour-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-driver-manila-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-driver-manila-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-driver-manila-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-driver-shared-resource-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-driver-shared-resource-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-driver-shared-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-external-provisioner",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-external-provisioner-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-external-provisioner-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-deployer",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-deployer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-builder",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-builder-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-docker-registry",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-dpu-cni-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-dpu-daemon-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-dpu-intel-ipu-p4sdk-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-dpu-intel-ipu-vsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-dpu-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-etcd",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-etcd-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-gcp-filestore-csi-driver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-gcp-pd-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-haproxy-router",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-haproxy-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-helm-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-helm-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-hypershift-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-insights-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-installer",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-installer-altinfra-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-installer-altinfra-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-installer-artifacts",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-installer-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-installer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-kube-proxy",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-kube-state-metrics",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-kube-state-metrics-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-local-storage-diskmaker",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-local-storage-diskmaker-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-local-storage-mustgather-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-local-storage-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-config-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-monitoring-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-monitoring-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-node-feature-discovery",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-node-feature-discovery-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-oauth-apiserver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-oauth-apiserver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-oauth-server-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-olm-catalogd-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-olm-catalogd-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-olm-operator-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-olm-operator-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-olm-rukpak-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-olm-rukpak-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openshift-controller-manager-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openshift-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openstack-cinder-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openstack-cinder-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openstack-cloud-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-framework-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-lifecycle-manager",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-lifecycle-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-marketplace",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-registry",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-sdk-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-sdk-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ovn-kubernetes-microshift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ovn-kubernetes-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-powervs-block-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-powervs-block-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-powervs-block-csi-driver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-prometheus-config-reloader",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-prometheus-config-reloader-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-prometheus-operator-admission-webhook-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-prometheus-operator-admission-webhook-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-prometheus-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-prometheus-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-sdn-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-sdn-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-secrets-store-csi-driver-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-secrets-store-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-secrets-store-csi-driver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-secrets-store-csi-mustgather-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-secrets-store-csi-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-service-ca-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-smb-csi-driver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-telemeter-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-thanos-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tools-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vertical-pod-autoscaler-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-cloud-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-cluster-api-controllers-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-cluster-api-controllers-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-operator-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-syncer-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-syncer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/topology-aware-lifecycle-manager-aztp-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/topology-aware-lifecycle-manager-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/topology-aware-lifecycle-manager-precache-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/topology-aware-lifecycle-manager-recovery-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/topology-aware-lifecycle-manager-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4-wincw/windows-machine-config-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4-wincw/windows-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift-clients",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "podman",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "redhat/redhat-operator-index",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "rhacm2/kube-state-metrics-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "skopeo",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Out of support scope",
        "package_name": "odf4/cephcsi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/mcg-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/mcg-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/mcg-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/ocs-client-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/ocs-metrics-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/ocs-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/odf-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/odf-cloudnative-pg-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/odf-csi-addons-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/odf-csi-addons-sidecar-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Out of support scope",
        "package_name": "odf4/odf-multicluster-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/odf-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/odf-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/odr-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/rook-ceph-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/code-sshd-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/devspaces-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/devspaces-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/machineexec-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces-tech-preview/idea-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/traefik-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/udi-base-rhel10",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/udi-base-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/udi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Not affected",
        "package_name": "rhosdt/opentelemetry-collector-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Not affected",
        "package_name": "rhosdt/opentelemetry-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Not affected",
        "package_name": "rhosdt/opentelemetry-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Not affected",
        "package_name": "rhosdt/opentelemetry-target-allocator-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Not affected",
        "package_name": "rhosdt/tempo-gateway-opa-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Not affected",
        "package_name": "rhosdt/tempo-gateway-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Not affected",
        "package_name": "rhosdt/tempo-jaeger-query-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Not affected",
        "package_name": "rhosdt/tempo-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Not affected",
        "package_name": "rhosdt/tempo-query-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Not affected",
        "package_name": "rhosdt/tempo-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Not affected",
        "package_name": "rhosdt/tempo-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Out of support scope",
        "package_name": "openshift4-wincw/windows-machine-config-operator-bundle",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Out of support scope",
        "package_name": "openshift4-wincw/windows-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/argocd-agent-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/argocd-extensions-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Affected",
        "package_name": "openshift-gitops-1/argocd-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Affected",
        "package_name": "openshift-gitops-1/argocd-rhel9",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/argo-rollouts-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/console-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/dex-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/gitops-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/gitops-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/gitops-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift on AWS",
        "fix_state": "Not affected",
        "package_name": "rosa",
        "cpe": "cpe:/a:redhat:openshift_service_on_aws:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/hostpath-provisioner-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/hostpath-provisioner-rhel8-operator",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/hyperconverged-cluster-operator",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/hyperconverged-cluster-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/hyperconverged-cluster-webhook-rhel8",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/hyperconverged-cluster-webhook-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/kubevirt-ssp-operator",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/kubevirt-ssp-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/kubevirt-tekton-tasks-create-datavolume-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/kubevirt-tekton-tasks-operator",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/kubevirt-template-validator",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/kubevirt-template-validator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/multus-dynamic-networks-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/ocp-virt-validation-checkup-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/passt-network-binding-plugin-cni-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/passt-network-binding-plugin-sidecar-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/sidecar-shim-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-api",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-api-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-artifacts-server",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-artifacts-server-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-apiserver",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-apiserver-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-cloner",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-cloner-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-controller",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-controller-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-importer",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-importer-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-operator",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-uploadproxy",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-uploadproxy-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-uploadserver",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-cdi-uploadserver-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-controller",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-controller-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-exportproxy",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-exportproxy-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-exportserver",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-exportserver-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-handler",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-handler-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-launcher",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-launcher-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-operator",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/virt-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/virt-synchronization-controller-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/wasp-agent-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "kubevirt",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "etcd",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "golang-github-Sirupsen-logrus",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/osp-director-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/osp-director-downloader",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/osp-director-operator",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/osp-director-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "etcd",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "golang-github-Sirupsen-logrus",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel9/osp-director-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel9/osp-director-downloader",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel9/osp-director-operator",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel9/osp-director-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/openstack-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/openstack-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/openstack-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/prometheus-podman-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/rabbitmq-cluster-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Out of support scope",
        "package_name": "quay/clair-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/quay-builder-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/quay-container-security-operator-bundle",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/quay-container-security-operator-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Out of support scope",
        "package_name": "quay/quay-operator-bundle",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Out of support scope",
        "package_name": "quay/quay-operator-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Out of support scope",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-ingress-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-vmaas-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/certificate-transparency-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/client-server-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/cosign-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/createtree-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/gitsign-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/policy-controller-operator-bundle",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/policy-controller-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/policy-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/rhtas-console-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/rhtas-operator-bundle",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/rhtas-rhel9-operator",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/trillian-database-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/trillian-logserver-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/trillian-logsigner-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/trillian-redis-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/updatetree-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Not affected",
        "package_name": "rhtpa/rhtpa-guac-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:1"
      },
      {
        "product_name": "Red Hat Web Terminal",
        "fix_state": "Out of support scope",
        "package_name": "web-terminal-tech-preview/web-terminal-exec-rhel8",
        "cpe": "cpe:/a:redhat:webterminal:1"
      },
      {
        "product_name": "Red Hat Web Terminal",
        "fix_state": "Out of support scope",
        "package_name": "web-terminal/web-terminal-exec-rhel8",
        "cpe": "cpe:/a:redhat:webterminal:1"
      },
      {
        "product_name": "Red Hat Web Terminal",
        "fix_state": "Out of support scope",
        "package_name": "web-terminal/web-terminal-exec-rhel9",
        "cpe": "cpe:/a:redhat:webterminal:1"
      },
      {
        "product_name": "Red Hat Web Terminal",
        "fix_state": "Not affected",
        "package_name": "web-terminal/web-terminal-tooling-rhel9",
        "cpe": "cpe:/a:redhat:webterminal:1"
      },
      {
        "product_name": "Security Profiles Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-security-profiles-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_security_profiles_operator:1"
      },
      {
        "product_name": "Security Profiles Operator",
        "fix_state": "Not affected",
        "package_name": "compliance/openshift-security-profiles-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_security_profiles_operator:1"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Not affected",
        "package_name": "stf/service-telemetry-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Not affected",
        "package_name": "stf/smart-gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-server-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-operator-bundle",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-65637\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-65637\nhttps://github.com/mjuanxd/logrus-dos-poc\nhttps://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md\nhttps://github.com/sirupsen/logrus/issues/1370\nhttps://github.com/sirupsen/logrus/pull/1376\nhttps://github.com/sirupsen/logrus/releases/tag/v1.8.3\nhttps://github.com/sirupsen/logrus/releases/tag/v1.9.1\nhttps://github.com/sirupsen/logrus/releases/tag/v1.9.3\nhttps://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSIRUPSENLOGRUS-5564391"
    ],
    "name": "CVE-2025-65637",
    "mitigation": {
      "value": "Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-10T09:10:14Z",
    "bugzilla": {
      "description": "usbmuxd: usbmuxd: Path Traversal vulnerability allows local privilege escalation",
      "id": "2420941",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2420941"
    },
    "cvss3": {
      "cvss3_base_score": "5.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L",
      "status": "draft"
    },
    "cwe": "CWE-35",
    "details": [
      "A Path Traversal vulnerability in usbmuxd allows local users to escalate to the service user.This issue affects usbmuxd: before 3ded00c9985a5108cfc7591a309f9a23d57a8cba.",
      "A local path traversal vulnerability in usbmuxd allows unprivileged users to send crafted messages to its world-writable UNIX socket, causing the daemon to create or delete files as the usbmux user. Due to insufficient validation of the PairRecordID field, attackers can escape the intended configuration directory, with a narrow race condition potentially enabling broader file overwrite. The issue is limited to local access and does not directly grant root privileges."
    ],
    "statement": "This issue is best classified as a Moderate vulnerability rather than an Important flaw because its impact is constrained to a local privilege boundary and a non-root service account. Exploitation requires local access to the system and interaction with a UNIX socket, with no remote attack vector or user interaction involved. While the lack of input validation allows path traversal leading to file deletion or creation, these operations are performed as the usbmux user, not as root, and therefore do not directly compromise full system integrity. The potential extension to arbitrary file overwrite relies on a tight race condition (TOCTOU), which reduces reliability and exploit consistency. There is no direct confidentiality impact and no automatic escalation beyond the service’s privilege scope, making the flaw security-relevant but limited in blast radius, aligning it with a medium (moderate) severity classification rather than a high-impact vulnerability.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "usbmuxd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "usbmuxd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "usbmuxd",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-66004\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-66004\nhttps://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-66004"
    ],
    "name": "CVE-2025-66004",
    "mitigation": {
      "value": "No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-17T18:48:30Z",
    "bugzilla": {
      "description": "tomcat: Client certificate verification bypass due to virtual host mapping",
      "id": "2440430",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2440430"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-1289",
    "details": [
      "Improper Input Validation vulnerability.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected.\nTomcat did not validate that the host name provided via the SNI \nextension was the same as the host name provided in the HTTP host header \nfield. If Tomcat was configured with more than one virtual host and the \nTLS configuration for one of those hosts did not require client \ncertificate authentication but another one did, it was possible for a \nclient to bypass the client certificate authentication by sending \ndifferent host names in the SNI extension and the HTTP host header field.\nThe vulnerability only applies if client certificate authentication is \nonly enforced at the Connector. It does not apply if client certificate \nauthentication is enforced at the web application.\nUsers are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fix the issue.",
      "A certificate validation flaw has been found in Apache Tomcat. omcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web application."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36790",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "tomcat9-1:9.0.117-2.el10_2"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12195",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2",
        "package": "tomcat"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 10",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12194",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
        "package": "jws6-tomcat-0:10.1.49-10.redhat_00008.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 8",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12194",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
        "package": "jws6-tomcat-0:10.1.49-10.redhat_00008.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 9",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12194",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
        "package": "jws6-tomcat-0:10.1.49-10.redhat_00008.1.el9jws"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-04T00:00:00Z",
        "advisory": "RHSA-2026:6569",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.21-0.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8334",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.54-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-66614\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-66614\nhttps://lists.apache.org/thread/vw6lxtlh2qbqwpb61wd3sv1flm2nttw7"
    ],
    "name": "CVE-2025-66614",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-12T05:36:59Z",
    "bugzilla": {
      "description": "tornado: Tornado Header Injection and XSS via reason argument",
      "id": "2421719",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2421719"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-79",
    "details": [
      "Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom \"reason\" phrases (the \"Not Found\" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.",
      "An unescaped input flaw has been discovered in the Tornado networking library. In Tornado, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom \"reason\" phrases (the \"Not Found\" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes)."
    ],
    "package_state": [
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/bitwarden-sdk-server-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-operator-bundle",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-operator-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "external secrets operator for Red Hat OpenShift - Tech Preview",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/bitwarden-sdk-server-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:0"
      },
      {
        "product_name": "external secrets operator for Red Hat OpenShift - Tech Preview",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-operator-bundle",
        "cpe": "cpe:/a:redhat:external_secrets_operator:0"
      },
      {
        "product_name": "external secrets operator for Red Hat OpenShift - Tech Preview",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-operator-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:0"
      },
      {
        "product_name": "external secrets operator for Red Hat OpenShift - Tech Preview",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:0"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-cni-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-pilot-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-sail-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Fix deferred",
        "package_name": "advanced-cluster-security/rhacs-collector-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhel10/keylime-registrar",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhel10/keylime-verifier",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/keylime-registrar",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/keylime-verifier",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/disk-image-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-ragas-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "python-pep517",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-cinder-backup",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-cinder-volume",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-haproxy",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-manila-share",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-mariadb",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-ovn-northd",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-rabbitmq",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-redis",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-cinder-backup",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-cinder-volume",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-haproxy",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-manila-share",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-mariadb",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ovn-northd",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-rabbitmq",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-redis",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-67724\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-67724\nhttps://github.com/tornadoweb/tornado/commit/9c163aebeaad9e6e7d28bac1f33580eb00b0e421\nhttps://github.com/tornadoweb/tornado/releases/tag/v6.5.3\nhttps://github.com/tornadoweb/tornado/security/advisories/GHSA-pr2v-jx2c-wg9f"
    ],
    "name": "CVE-2025-67724",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-12-14T22:17:42Z",
    "bugzilla": {
      "description": "uriparser: uriparser: Unbounded recursion and stack consumption via large input",
      "id": "2422120",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2422120"
    },
    "cvss3": {
      "cvss3_base_score": "2.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-674",
    "details": [
      "uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.",
      "A flaw was found in uriparser. This vulnerability allows unbounded recursion and stack consumption via large input containing many commas."
    ],
    "statement": "This vulnerability is rated Low for Red Hat because it requires local access and a specially crafted URI to trigger unbounded recursion, leading to stack consumption. The attack complexity is high, limiting its practical impact in most Red Hat deployments.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-11T00:00:00Z",
        "advisory": "RHSA-2026:7642",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "uriparser-main-1.0.0-2.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "uriparser",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "uriparser",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-67899\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-67899\nhttps://github.com/uriparser/uriparser/issues/282\nhttps://github.com/uriparser/uriparser/pull/284"
    ],
    "name": "CVE-2025-67899",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-28T19:30:30Z",
    "bugzilla": {
      "description": "cmd/go: cmd/go: Local code execution and arbitrary file write via malicious module version strings",
      "id": "2434438",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2434438"
    },
    "cvss3": {
      "cvss3_base_score": "6.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-78",
    "details": [
      "Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.",
      "A flaw was found in Golang's cmd/go module. This vulnerability allows a local attacker to achieve local code execution by downloading and building modules with specially crafted malicious version strings. On systems with Mercurial (hg) installed, this can occur when downloading modules from non-standard sources due to how external Version Control System (VCS) commands are constructed. Additionally, on systems with Git installed, providing malicious version strings to the toolchain can enable an attacker to write to arbitrary files on the filesystem. This issue is triggered by explicitly supplying these malicious version strings."
    ],
    "statement": "This issue is rated Moderate severity by Red Hat Product Security, because exploitation requires non-standard and intentional user behavior. \nThe attacker must explicitly supply a specially crafted module version string, which does not occur during normal Go module usage such as @latest or standard module paths, making the attack complexity high. \nAdditionally, user interaction is required, as the vulnerable behavior is only triggered when a user manually invokes the Go toolchain to download or build the malicious module.\nWhile successful exploitation can result in local code execution or arbitrary file modification, the combination of local access, manual input, and uncommon usage patterns significantly limits the likelihood of exploitation in typical environments.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7291",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-26-main-1.26.2-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7385",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-25-main-1.25.9-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "golang",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Out of support scope",
        "package_name": "go-toolset:rhel8/golang",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "golang",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-68119\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-68119\nhttps://go.dev/cl/736710\nhttps://go.dev/issue/77099\nhttps://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc\nhttps://pkg.go.dev/vuln/GO-2026-4338"
    ],
    "name": "CVE-2025-68119",
    "mitigation": {
      "value": "No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-05T17:48:44Z",
    "bugzilla": {
      "description": "crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption",
      "id": "2437111",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111"
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "details": [
      "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.",
      "A flaw was found in the crypto/tls component. This vulnerability occurs during Transport Layer Security (TLS) session resumption when certificate authority (CA) settings are modified between the initial and resumed handshakes. An attacker could exploit this to bypass certificate validation, allowing a client or server to establish a connection that should have been rejected. This could lead to an authentication bypass under specific conditions."
    ],
    "statement": "This is a moderate flaw because it only occurs under specific conditions, such as TLS session resumption with runtime changes to certificate authority settings. Exploitation is not straightforward and requires a controlled setup. The impact is limited to certificate validation within the same component and does not affect system availability.",
    "affected_release": [
      {
        "product_name": "Cryostat 4 on RHEL 9",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3186",
        "cpe": "cpe:/a:redhat:cryostat:4::el9",
        "package": "cryostat/cryostat-storage-rhel9:4.1.1-3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6278",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "automation-gateway-proxy-0:2.5.10-4.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6278",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "automation-gateway-proxy-0:2.6.14-1.el9"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6277",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "automation-gateway-proxy-0:2.6.14-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2706",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "golang-0:1.25.7-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2914",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "grafana-0:10.2.6-22.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3035",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "grafana-pcp-0:5.3.0-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3092",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "golang-github-openprinting-ipp-usb-0:0.9.27-5.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3297",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "buildah-2:1.41.8-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3336",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "podman-7:5.6.0-12.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3343",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "skopeo-2:1.20.0-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3752",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "osbuild-composer-0:149-5.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3840",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "image-builder-0:31-4.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3864",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "delve-0:1.25.2-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3971",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "rhc-worker-playbook-0:0.2.3-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4164",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "git-lfs-0:3.6.1-7.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4174",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "opentelemetry-collector-0:0.144.0-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4892",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "rhc-1:0.3.4-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5146",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "yggdrasil-0:0.4.8-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19013",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "delve-0:1.26.1-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22141",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "go-fdo-client-0:1.0.0-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22141",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "go-fdo-server-0:1.0.1-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22450",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "osbuild-composer-0:165.1-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22937",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "image-builder-0:52.1-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14868",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "buildah-2:1.39.8-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16696",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "skopeo-2:1.18.1-3.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17040",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "podman-6:5.4.0-15.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17084",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gvisor-tap-vsock-6:0.8.5-2.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17686",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "osbuild-composer-0:134.1-6.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3192",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "golang-0:1.25.7-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3506",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "yggdrasil-0:0.4.7-2.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3816",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "grafana-pcp-0:5.2.2-4.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3831",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "grafana-0:10.2.6-21.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3843",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "delve-0:1.25.2-2.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3970",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "rhc-worker-playbook-0:0.2.3-3.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3977",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "golang-github-openprinting-ipp-usb-0:0.9.27-3.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4166",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "git-lfs-0:3.6.1-2.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:4256",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "opentelemetry-collector-0:0.144.0-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4907",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "rhc-1:0.3.2-2.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2708",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "go-toolset:rhel8-8100020260212045823.a3795dee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3187",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "grafana-pcp-0:5.1.1-12.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3188",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "grafana-0:9.2.10-28.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3898",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "osbuild-composer-0:101.4-4.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3985",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "git-lfs-0:3.4.1-8.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4672",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "container-tools:rhel8-8100020260311202035.afee755d"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4952",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "rhc-1:0.2.5-4.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19634",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "container-tools:rhel8-8060020260515174849.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51288",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "container-tools:rhel8-8060020260803064027.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51288",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "container-tools:rhel8-8060020260803064027.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19634",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "container-tools:rhel8-8060020260515174849.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19634",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "container-tools:rhel8-8060020260515174849.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49944",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "container-tools:rhel8-8080020260721142025.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49944",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "container-tools:rhel8-8080020260721142025.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18913",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "containernetworking-plugins-1:1.9.0-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22714",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "osbuild-composer-0:165.1-2.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23228",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "image-builder-0:52.1-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2709",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "golang-0:1.25.7-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2920",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "grafana-0:10.2.6-18.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3040",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "grafana-pcp-0:5.1.1-12.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3291",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "runc-4:1.4.0-2.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3298",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "buildah-2:1.41.8-2.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3337",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "podman-6:5.6.0-14.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3340",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "skopeo-2:1.20.0-3.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3341",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "containernetworking-plugins-1:1.7.1-3.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3753",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "osbuild-composer-0:149-4.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3839",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "image-builder-0:31-3.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3842",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "delve-0:1.25.2-2.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3928",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "git-lfs-0:3.6.1-7.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4177",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "opentelemetry-collector-0:0.144.0-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4901",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "rhc-1:0.2.7-2.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16102",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "buildah-1:1.26.11-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25248",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "podman-2:4.4.1-22.el9_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25250",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "skopeo-2:1.11.4-0.1.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25251",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "containernetworking-plugins-1:1.2.0-3.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25252",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "buildah-1:1.29.7-1.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25253",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "runc-4:1.2.9-1.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47719",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "golang-0:1.25.9-1.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47721",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "grafana-pcp-0:5.1.1-5.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47722",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "grafana-0:9.0.9-12.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:48036",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "osbuild-composer-0:76.1-6.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49600",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "rhc-1:0.2.2-1.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12028",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "podman-4:4.9.4-20.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12029",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "skopeo-2:1.14.5-2.el9_4.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12030",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "buildah-2:1.33.13-3.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12031",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "runc-4:1.2.9-1.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12032",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "containernetworking-plugins-1:1.4.0-6.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12033",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gvisor-tap-vsock-6:0.7.3-5.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:4267",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "opentelemetry-collector-0:0.144.0-1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47712",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "golang-0:1.25.9-1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47714",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "grafana-0:9.2.10-27.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47716",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "grafana-pcp-0:5.1.1-8.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47910",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "osbuild-composer-0:101.3-4.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49509",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "rhc-1:0.2.4-8.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11749",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "buildah-2:1.39.6-2.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19475",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "osbuild-composer-0:132.2-6.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3193",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "golang-0:1.25.7-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3817",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "grafana-pcp-0:5.1.1-12.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3833",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "grafana-0:10.2.6-18.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3929",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "git-lfs-0:3.6.1-2.el9_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:4264",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "opentelemetry-collector-0:0.144.0-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5077",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "rhc-1:0.2.7-1.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7854",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "podman-5:5.4.0-20.el9_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9097",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "runc-4:1.2.9-3.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9098",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "skopeo-2:1.18.1-5.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9108",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gvisor-tap-vsock-6:0.8.5-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9109",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "containernetworking-plugins-1:1.6.2-3.el9_6"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26527",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "containernetworking-plugins-1:1.4.0-6.rhaos4.12.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26527",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "skopeo-2:1.9.4-8.rhaos4.12.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26541",
        "cpe": "cpe:/a:redhat:openshift:4.13::el8",
        "package": "containernetworking-plugins-1:1.4.0-7.rhaos4.13.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26541",
        "cpe": "cpe:/a:redhat:openshift:4.13::el8",
        "package": "podman-3:4.4.1-19.rhaos4.13.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26541",
        "cpe": "cpe:/a:redhat:openshift:4.13::el8",
        "package": "skopeo-2:1.11.3-6.rhaos4.13.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28886",
        "cpe": "cpe:/a:redhat:openshift:4.14::el8",
        "package": "containernetworking-plugins-1:1.4.0-6.rhaos4.14.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28886",
        "cpe": "cpe:/a:redhat:openshift:4.14::el8",
        "package": "podman-3:4.4.1-25.rhaos4.14.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:28961",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "containernetworking-plugins-1:1.4.0-6.rhaos4.15.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17595",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "podman-5:5.2.2-18.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:5866",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "containernetworking-plugins-1:1.4.0-8.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:5866",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "runc-4:1.2.9-4.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:5866",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "skopeo-2:1.16.1-5.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17446",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "podman-5:5.2.2-11.rhaos4.18.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6552",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "skopeo-2:1.16.1-5.rhaos4.18.el9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:5876",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "runc-4:1.2.5-5.rhaos4.19.el9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:5876",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "skopeo-2:1.18.1-5.rhaos4.19.el9"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54757",
        "cpe": "cpe:/a:redhat:openstack:16.2::el8",
        "package": "etcd-0:3.3.23-22.el8ost"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1 for RHEL 9",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:28047",
        "cpe": "cpe:/a:redhat:openstack:17.1::el9",
        "package": "etcd-0:3.4.26-9.5.el9ost"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18.0",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:7885",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "golang-github-openstack-k8s-operators-os-diff-0:0.1.1-18.0.20260225161428.32d52e7.el9ost"
      },
      {
        "product_name": "Red Hat Satellite 6.16 for RHEL 8",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5971",
        "cpe": "cpe:/a:redhat:satellite:6.16::el8",
        "package": "yggdrasil-worker-forwarder-0:0.0.3-4.el8sat"
      },
      {
        "product_name": "Red Hat Satellite 6.16 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5971",
        "cpe": "cpe:/a:redhat:satellite:6.16::el9",
        "package": "yggdrasil-worker-forwarder-0:0.0.3-4.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_maintenance:6.17::el9",
        "package": "foreman-0:3.14.0.14-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_maintenance:6.17::el9",
        "package": "libcomps-0:0.1.23-0.3.el9pc"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_maintenance:6.17::el9",
        "package": "python-brotli-0:1.2.0-0.1.el9pc"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_maintenance:6.17::el9",
        "package": "python-django-0:4.2.28-0.1.el9pc"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_maintenance:6.17::el9",
        "package": "python-pulp-container-0:2.22.3-1.el9pc"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_maintenance:6.17::el9",
        "package": "python-pulp-rpm-0:3.27.10-2.el9pc"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_maintenance:6.17::el9",
        "package": "rubygem-fog-kubevirt-0:1.5.1-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_maintenance:6.17::el9",
        "package": "rubygem-foreman_kubevirt-0:0.4.3-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_maintenance:6.17::el9",
        "package": "rubygem-katello-0:4.16.0.14-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_maintenance:6.17::el9",
        "package": "rubygem-rubyipmi-0:0.13.0-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_maintenance:6.17::el9",
        "package": "satellite-0:6.17.7-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_maintenance:6.17::el9",
        "package": "yggdrasil-worker-forwarder-0:0.0.3-4.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_utils:6.17::el9",
        "package": "foreman-0:3.14.0.14-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_utils:6.17::el9",
        "package": "libcomps-0:0.1.23-0.3.el9pc"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_utils:6.17::el9",
        "package": "python-brotli-0:1.2.0-0.1.el9pc"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_utils:6.17::el9",
        "package": "python-django-0:4.2.28-0.1.el9pc"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_utils:6.17::el9",
        "package": "python-pulp-container-0:2.22.3-1.el9pc"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_utils:6.17::el9",
        "package": "python-pulp-rpm-0:3.27.10-2.el9pc"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_utils:6.17::el9",
        "package": "rubygem-fog-kubevirt-0:1.5.1-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_utils:6.17::el9",
        "package": "rubygem-foreman_kubevirt-0:0.4.3-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_utils:6.17::el9",
        "package": "rubygem-katello-0:4.16.0.14-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_utils:6.17::el9",
        "package": "rubygem-rubyipmi-0:0.13.0-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_utils:6.17::el9",
        "package": "satellite-0:6.17.7-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5970",
        "cpe": "cpe:/a:redhat:satellite_utils:6.17::el9",
        "package": "yggdrasil-worker-forwarder-0:0.0.3-4.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.18 for RHEL 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5968",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "yggdrasil-worker-forwarder-0:0.0.3-4.el9sat"
      },
      {
        "product_name": "Streams for Apache Kafka 3.2.0",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13571",
        "cpe": "cpe:/a:redhat:amq_streams:3.2::el9",
        "package": "golang-github-danielqsj-kafka_exporter"
      },
      {
        "product_name": "cert-manager operator for Red Hat OpenShift 1.17",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5645",
        "cpe": "cpe:/a:redhat:cert_manager:1.17::el9",
        "package": "cert-manager/jetstack-cert-manager-acmesolver-rhel9:1774342146"
      },
      {
        "product_name": "cert-manager operator for Red Hat OpenShift 1.17",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5645",
        "cpe": "cpe:/a:redhat:cert_manager:1.17::el9",
        "package": "cert-manager/jetstack-cert-manager-rhel9:1774341716"
      },
      {
        "product_name": "Compliance Operator 1",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8433",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1::el9",
        "package": "compliance/openshift-compliance-operator-bundle:1776237332"
      },
      {
        "product_name": "Custom Metric Autoscaler 2.19",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26636",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2.19::el9",
        "package": "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9:1780101239"
      },
      {
        "product_name": "DevWorkspace Operator 0.4",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5851",
        "cpe": "cpe:/a:redhat:devworkspace:0.40::el9",
        "package": "devworkspace/devworkspace-rhel9-operator:1773953459"
      },
      {
        "product_name": "external secrets operator for Red Hat OpenShift 1.0",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40924",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1.0::el9",
        "package": "external-secrets-operator/external-secrets-rhel9:1784113402"
      },
      {
        "product_name": "File Integrity Operator 1",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22627",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1::el9",
        "package": "compliance/openshift-file-integrity-rhel8-operator:1780389566"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.0",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7052",
        "cpe": "cpe:/a:redhat:logging:6.0::el9",
        "package": "openshift-logging/eventrouter-rhel9:1774879741"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.2",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4500",
        "cpe": "cpe:/a:redhat:logging:6.2::el9",
        "package": "openshift-logging/eventrouter-rhel9:1772560410"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift 6.4",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4498",
        "cpe": "cpe:/a:redhat:logging:6.4::el9",
        "package": "openshift-logging/eventrouter-rhel9:1772551200"
      },
      {
        "product_name": "mirror registry for Red Hat OpenShift 2.0",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28441",
        "cpe": "cpe:/a:redhat:mirror_registry:2.0::el8",
        "package": "openshift/mirror-registry-rhel8:1782177012"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13542",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/discovery-rhel9:1776457396"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9848",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el9",
        "package": "multicluster-engine/discovery-rhel9:1776103237"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.7",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5636",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.7::el9",
        "package": "multicluster-engine/discovery-rhel9:1773091107"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8218",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/discovery-rhel9:1774913711"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11414",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.9::el9",
        "package": "multicluster-engine/discovery-rhel9:1776435357"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5110",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1773650627"
      },
      {
        "product_name": "Network Observability (NETOBSERV) 1.11.1",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6428",
        "cpe": "cpe:/a:redhat:network_observ_optr:1.11::el9",
        "package": "network-observability/network-observability-cli-rhel9:1773992622"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-velero-rhel9:1785180878"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29854",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-velero-rhel9:1779809598"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4170",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-velero-rhel9:1771857537"
      },
      {
        "product_name": "OpenShift Developer Tools and Services 1.6.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:4270",
        "cpe": "cpe:/a:redhat:source_to_image:1.6::el8",
        "package": "source-to-image/source-to-image-rhel8:1773214142"
      },
      {
        "product_name": "OpenShift Developer Tools and Services 1.6.2",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:4270",
        "cpe": "cpe:/a:redhat:source_to_image:1.6::el8",
        "package": "source-to-image/source-to-image-rhel9:1773214747"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36873",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/subctl-rhel9:1782945263"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25127",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/subctl-rhel9:1780238563"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8151",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/subctl-rhel9:1774085848"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4466",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1773235880"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.9",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4467",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1773235860"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/receptor-rhel9:1777391542"
      },
      {
        "product_name": "Red Hat Developer Hub 1.8",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3089",
        "cpe": "cpe:/a:redhat:rhdh:1.8::el9",
        "package": "rhdh/rhdh-rhel9-operator:1771440517"
      },
      {
        "product_name": "Red Hat Edge Manager 1.0",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36651",
        "cpe": "cpe:/a:redhat:edge_manager:1.0::el9",
        "package": "rhem/flightctl-ui-rhel9:1783502438"
      },
      {
        "product_name": "Red Hat Edge Manager 1.1",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40945",
        "cpe": "cpe:/a:redhat:edge_manager:1.1::el10",
        "package": "rhem/flightctl-ui-rhel10:1784194574"
      },
      {
        "product_name": "Red Hat Edge Manager 1.1",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:40118",
        "cpe": "cpe:/a:redhat:edge_manager:1.1::el9",
        "package": "rhem/flightctl-ui-rhel9:1784127736"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7291",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-26-main-1.26.2-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7385",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-25-main-1.25.9-1.hum1"
      },
      {
        "product_name": "Red Hat Lightspeed (formerly Insights) for Runtimes 1.0",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4220",
        "cpe": "cpe:/a:redhat:lightspeed_for_runtimes:1.0::el9",
        "package": "rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator:1.0.1-1773067492"
      },
      {
        "product_name": "Red Hat Migration Toolkit 1.8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41928",
        "cpe": "cpe:/a:redhat:rhmt:1.8::el8",
        "package": "rhmtc/openshift-migration-registry-rhel8:1783914276"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6429",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1774269698"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6226",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1774245790"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3782",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-rhel9-operator:1772340363"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.6.4",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5549",
        "cpe": "cpe:/a:redhat:openshift_builds:1.6::el9",
        "package": "openshift-builds/openshift-builds-waiters-rhel9:1774334066"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.7.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10158",
        "cpe": "cpe:/a:redhat:openshift_builds:1.7::el9",
        "package": "openshift-builds/openshift-builds-waiters-rhel9:1776846936"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.7.3",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11331",
        "cpe": "cpe:/a:redhat:openshift_builds:1.7::el9",
        "package": "openshift-builds/openshift-builds-waiters-rhel9:1776846936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1777002694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/egress-router-cni-rhel8:1777001625"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1777001562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/network-tools-rhel8:1777002936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1777042122"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1777001567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1777002279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1777002206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel8:1777001821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1777002716"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1777001811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1777001595"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1777001647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1777001622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1777001637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1777001993"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1777002058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1777001588"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1777002145"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1777001819"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1777001657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1777001578"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1777002721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1777001896"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1777001576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1777001621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1777001630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cli:1776999989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cli-artifacts:1777002317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cloud-credential-operator:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1777002062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1777001657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-autoscaler:1777001639"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1777001616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1777001722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-bootstrap:1777001579"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1777001660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1777001660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1777001584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-config-operator:1777001860"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1777001588"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-dns-operator:1777001846"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1777001876"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1777001943"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1777001611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1777001561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1777001575"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1777001571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1777002164"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-machine-approver:1777001580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1777001813"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-network-operator:1777001698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-node-tuning-operator:1777002719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1777001569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1777001603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1777001612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1777001775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-samples-operator:1777001570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-storage-operator:1777001574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-version-operator:1777001558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-configmap-reloader:1777001608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-console:1777002039"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-console-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1777001571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-coredns:1777001653"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1777001577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1777001777"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1777001621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1777001656"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1777001606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-attacher:1777001646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1777001646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-provisioner:1776999972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1776999972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-resizer:1776999948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1776999948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1776999951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1776999951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-livenessprobe:1776999947"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1776999947"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1776999949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1776999949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1777001741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1777001741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1777001992"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-docker-builder:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-docker-registry:1777001681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-etcd:1777001596"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1777001898"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1777002697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1777001692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1777001837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-hyperkube:1777304752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-hypershift-rhel8:1777001784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1777001854"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1777001574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1777001888"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1777001586"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1777001561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1777002168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1777001585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-installer:1777000374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-installer-artifacts:1777003222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1777001763"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1777001618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-proxy:1777001642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1776999981"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-state-metrics:1777001815"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1777001549"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1777001541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1777001647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1777001659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1777001636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1777001608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1777001598"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-config-operator:1777002732"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-admission-controller:1777001535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-cni:1777001584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1777001612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1777001628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1777001576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-must-gather:1777000645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1777002718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1777001624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-proxy:1777001606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1777002057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1777002697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1777002725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1777001617"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1777001581"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1777001775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1777001580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1777001618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-machine-controllers:1777001573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1777001630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-marketplace:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-registry:1777001671"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1777001649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovn-kubernetes:1777002178"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel8:1777001818"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-pod:1777304565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1777001521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1777001566"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1777001771"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1777042146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus:1777001745"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1777001893"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1777002720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1777001726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prom-label-proxy:1777001535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-sdn-rhel8:1777001790"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-service-ca-operator:1777001589"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-telemeter:1777001614"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-tests:1777002345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-thanos-rhel8:1777001839"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1777001605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1777001655"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1777001573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1777001605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1777001823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1777001631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1777001640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1777001645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-08T00:00:00Z",
        "advisory": "RHSA-2026:14100",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-tests:1778173182"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1779864120"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/egress-router-cni-rhel8:1779864235"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1779864128"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/network-tools-rhel8:1779313037"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1779889676"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1779889641"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1778765353"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1778765274"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel8:1779889723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1779863997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1779864079"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1779864508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1779864192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1779889720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1779863999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1779889660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1779889680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1779863969"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1779864074"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1779863989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1779889642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1779863994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1779864633"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1779864005"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1779889629"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1779889720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1779864603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1779863994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1779864132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1779864485"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cli:1779889704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cli-artifacts:1778765373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cloud-credential-operator:1779864236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1779889678"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1779864074"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-autoscaler:1779863413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1779864513"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1779864055"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-bootstrap:1779864189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1779864740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1779864740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1779864043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-config-operator:1779863993"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1779863952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1779864018"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-dns-operator:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1779863985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1779864123"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1779864006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1779863976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1779864264"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1779889616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1779889647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1779864436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-machine-approver:1779864047"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1779864102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-network-operator:1779889634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1779890827"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1779864733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1779864442"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1779864212"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1779889609"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-samples-operator:1779863398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-storage-operator:1779864003"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-version-operator:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-configmap-reloader:1779863974"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-console:1779864415"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-console-operator:1779889659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-coredns:1779864040"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1779889631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1779864020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1779864063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1779863966"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1779863998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1779864441"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-attacher:1779871348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1779871348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-provisioner:1779864793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1779864793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-resizer:1779864022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1779864022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1779864025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1779864025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-livenessprobe:1779864161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1779864161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1779864052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1779864052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1779889611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1779889611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1779889636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-docker-builder:1779863452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-docker-registry:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-etcd-rhel9:1779890788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1779864509"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1779864100"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1779889604"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1779863996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-hyperkube:1779864503"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-hypershift-rhel8:1779864639"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1779889658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1779864019"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1779889649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1779889642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1779864104"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1779863998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1779864066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1779864162"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-installer:1779864501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-installer-artifacts:1778766542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1779890216"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1779864028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-proxy:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1779889644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-state-metrics:1779864165"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1779889585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1779864651"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1779863394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1779864348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-operator:1779864206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1779864736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1779864245"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1779864151"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1779864229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-config-operator:1779864726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-admission-controller:1779864390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-cni:1779864023"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1779889657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1779863412"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1779863416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-must-gather:1778765257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1779864053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1779864236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel8:1779889646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1779864046"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1779864015"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-proxy:1779863392"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1779889638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1779889640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1779889694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1779863972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1779863952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1779864222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1779889602"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1779863995"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1779889649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-marketplace:1779864043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-registry:1779864451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1779864238"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes:1779891613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1779891537"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1779891613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-pod:1779864280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1779863962"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1779864153"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1779864168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1779864213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus:1779863444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1779863390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1779863389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-operator:1779864228"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1779864564"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prom-label-proxy:1779863397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-sdn-rhel8:1778765374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-service-ca-operator:1779864304"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-telemeter:1779889631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-tests:1779313164"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-thanos-rhel8:1779889664"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1779864199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1779864192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1779864001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1779864199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1779889644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1779864320"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1779889619"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1779889628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1781832069"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/egress-router-cni-rhel8:1781827713"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1781833206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/network-tools-rhel8:1782129179"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1781822901"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1781833466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1782127696"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1781833322"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1782216845"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1781830130"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1782216854"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1781819493"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1781819603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1781868616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1781819513"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1781833661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1781819822"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1781819512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1781819805"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1781819745"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1781818863"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1781819781"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1781819692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1781819698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1781819656"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1781868652"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1781819470"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1781819881"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel8:1781819751"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1781829330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1781832955"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1781829368"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1781833531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cli:1781822479"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cli-artifacts:1781834044"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cloud-credential-operator:1781831033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1781822948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1781825212"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-autoscaler:1781832677"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1781832430"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1781825958"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-bootstrap:1781833284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1781829565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1781829565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1781833550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-config-operator:1781833340"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1781833112"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1781833322"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-dns-operator:1781831006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1781831567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1781833430"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1781870101"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1781822570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1781830075"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1781823446"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1781824178"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1781829614"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-machine-approver:1781829389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1781828997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-network-operator:1781821261"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-node-tuning-operator:1782216731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1782216731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-olm-operator-rhel8:1781826209"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1781831715"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1781830986"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1781826201"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1781832985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-samples-operator:1781833442"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-storage-operator:1781829398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-version-operator:1781832709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-configmap-reloader:1781822629"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-console:1782157414"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-console-operator:1781833577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1781831052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-coredns:1781822636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1781822560"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1781825092"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1781826440"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1781830702"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1781827287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1781832976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-attacher:1781828724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1781828724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-provisioner:1781822715"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1781822715"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-resizer:1781823513"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1781823513"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1781821049"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1781821049"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-livenessprobe:1781819040"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1781819040"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1781818917"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1781818917"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1781827065"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1781827065"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1781832726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-docker-builder:1781826870"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-docker-registry:1781826159"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-etcd-rhel9:1782216611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1781821907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1781826043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1781825997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1781819765"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1782216888"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-hypershift-rhel8:1781833099"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1781831657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1781821043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1781821508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1781820749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1781821461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1781820825"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1781819707"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1781833269"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-installer:1781823409"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-installer-artifacts:1781835922"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1782216105"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1781825244"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-proxy:1781832739"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1781819398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-state-metrics:1781827845"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1781830971"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1781823885"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1781825816"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1781826689"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-operator:1781830104"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1781819563"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1781819694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1781825901"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1781832734"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-config-operator:1781832547"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-admission-controller:1781833167"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-cni:1781828553"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1781833471"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1781828311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1781828431"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-must-gather:1781826507"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1781833326"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1781832621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel8:1781819738"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1781819443"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1781833590"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-proxy:1781822612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1781821057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-catalogd-rhel8:1781833535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel8:1781823438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1781833151"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1781833212"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1781829624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1781824222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1781831124"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1781828708"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1781833481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1781833795"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-marketplace:1781828500"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-registry:1781833422"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1781818967"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes:1782217893"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1782217791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1782217893"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-pod:1781829374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1781825510"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1781825615"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1781822570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1781822057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus:1781832427"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1781830427"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1781829139"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1781833422"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-operator:1781832230"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1781831513"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prom-label-proxy:1781827294"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-sdn-rhel8:1781835508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-service-ca-operator:1781833534"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-telemeter:1781830062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-tests:1782189317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-thanos-rhel8:1781831240"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1781819420"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1781818924"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1781819508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1781819553"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1781819420"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1781818924"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1781819511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1781819708"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1781832997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1781832741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1781824987"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/egress-router-cni-rhel8:1781826508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/kube-metrics-server-rhel8:1781820573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1781826931"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/network-tools-rhel8:1782126913"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1781930724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1781867531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1782132196"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1781816156"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1781929994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1781815915"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1781928033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel9:1781926841"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel9:1781926884"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1781813131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel9:1781926849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1781926853"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1781926827"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1781927004"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1781926868"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1781926926"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1781926888"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1781926860"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1781926879"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1781926794"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1781813134"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1781926856"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1781813145"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1782184225"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel8:1781813146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1781870376"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1781930102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1781930664"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1781930621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cli:1781813947"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cli-artifacts:1781869250"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cloud-credential-operator:1781814495"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1781928798"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1781930326"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1781926015"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1781930480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1781930548"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1781930027"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1781929736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1781928593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1781930327"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1781928265"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1781927284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1781926913"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1781930077"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1781930419"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1781929859"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1781928857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1781929964"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1781928574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1781928951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1781930146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1781928141"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1781929468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1781930494"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1781930458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1782098995"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-olm-operator-rhel8:1781821819"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1781930470"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1781929130"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel9:1781930019"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1781928986"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1781926002"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1781927906"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1781930063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1781930298"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-console:1782127091"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-console-rhel9-operator:1781930063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1781852384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-coredns-rhel9:1781927931"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1781814187"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1781927907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1781927460"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1781816092"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1781927280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1781930025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1781930169"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-provisioner:1781815301"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1781815301"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-resizer:1781817132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1781817132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1781929184"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-livenessprobe:1781815761"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1781815761"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1781817091"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1781817091"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1781930500"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1781930098"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-docker-builder:1781817074"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1781927681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-etcd-rhel9:1781930086"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1781927538"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1781928696"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1781814221"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1781928834"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1781930846"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-hypershift-rhel9:1781930442"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1781928003"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1781927102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1781952937"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1781813998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1781927257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel9:1781927477"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1781813154"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1781930053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer:1781868012"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer-altinfra-rhel8:1781815301"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer-artifacts:1781833876"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1781926117"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter-rhel9:1781927237"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1781929365"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1781817036"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1781927924"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1781930420"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1781930144"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1781927707"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1781926857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1781926775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1781928369"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1781930296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1781930033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-config-operator:1781869893"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1781927715"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-cni:1781823248"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1781930625"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1781824710"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1781868159"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-must-gather:1781817148"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1781814818"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1781927060"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1781926790"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1781926777"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1781930271"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1781926020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1781929268"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-catalogd-rhel8:1781829419"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel8:1781814763"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1781828546"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1781930638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1781930620"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1781927556"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1781821001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1781927317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1781930056"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel8:1781815330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1781930185"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1781930497"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1781929172"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1781930903"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1781931028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-pod-rhel9:1781928057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1781814311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1781927955"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1781927651"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1781928753"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus:1781825365"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1781869521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1781926922"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1781822465"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1781930050"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1781930335"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prom-label-proxy:1781817448"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-sdn-rhel9:1781930683"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1781930320"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-telemeter-rhel9:1781927297"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-tests:1782127009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-thanos-rhel8:1781817344"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1781813131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1781926856"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1781926904"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1781926812"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1781813131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1781926856"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1781926899"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1781926877"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1781820458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28964",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1781930125"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1778712094"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1778710338"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1778711456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1778710367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/driver-toolkit-rhel9:1778711050"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/egress-router-cni-rhel9:1778709318"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/frr-rhel9:1778701092"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1778711399"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1778711660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/network-tools-rhel9:1778718976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1778711674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1778711701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1778711791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1778711754"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1778711558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1778712111"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1778711782"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1778709420"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1778707346"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1778707380"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1778706811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1778707968"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1778707697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1778707580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1778706759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1778708031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1778708041"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1778707987"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1778707251"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1778707728"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1778707699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1778710129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1778718808"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1778711719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1778709794"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1778711768"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1778715516"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cli-rhel9:1778701275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1778710063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1778711773"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1778710542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1778710806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1778711741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1778709640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1778710891"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1778711802"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1778710438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1778710279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1778709692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1778709724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1778710173"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1778711613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1778709691"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1778711680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1778709871"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1778710213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1778711635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1778711609"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1778710421"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1778712033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1778710716"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1778709729"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1778710367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1778710661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1778709393"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1778710617"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1778709403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1778711783"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1778710126"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1778710517"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-update-keys-rhel9:1778709453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1778710545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1778710326"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-console-rhel9:1778718159"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-console-rhel9-operator:1778711749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1778710525"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-coredns-rhel9:1778710280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1778707878"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1778706645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1778707862"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1778710445"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9-operator:1778709335"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1778709792"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1778710349"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1778701149"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1778700996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1778700848"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1778700853"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1778700834"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1778709405"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1778710562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-deployer-rhel9:1778715239"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1778710258"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1778710229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-etcd-rhel9:1778709845"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1778708017"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1778707997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1778707723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1778708241"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1778711747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-haproxy-router-rhel9:1778711436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1778709689"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-hypershift-rhel9:1778710288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1778710227"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1778709545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1778711793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1778711557"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1778711683"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1778707299"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1778709453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1778711880"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1778710754"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-rhel9:1778710373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-agent-rhel9:1778706770"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1778707494"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-rhel9:1778707957"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-static-ip-manager-rhel9:1778707964"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-keepalived-ipfailover-rhel9:1778710806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1778711543"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1778701099"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1778709982"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1778710673"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1778710837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1778709447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1778707722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1778707724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1778707284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1778711757"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1778710857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1778711867"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-os-images-rhel9:1778718112"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1778718013"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1778711711"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1778711618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1778709750"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1778710823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1778711608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1778710881"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-must-gather-rhel9:1778702552"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-networking-console-plugin-rhel9:1778517109"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1778711621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1778710845"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1778707466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1778707832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1778710582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1778709208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1778709413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1778711551"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1778710351"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1778710181"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1778711581"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1778710026"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1778711478"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1778709328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1778711721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1778710093"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1778710263"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1778710541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1778709398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1778709325"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1778710391"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1778710176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-pod-rhel9:1778711650"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1778707884"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1778707466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1778706638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1778707549"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1778711553"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1778709872"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1778709287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1778709431"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-rhel9:1778710296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1778709906"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1778710862"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1778710475"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-telemeter-rhel9:1778711679"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-tests-rhel9:1778715654"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-thanos-rhel9:1778710497"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-tools-rhel9:1778701268"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1778707501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1778707849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1778707857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1778707857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1778707501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1778707849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1778707482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1778707873"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1778709987"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1778710215"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1776170839"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1776169938"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/network-tools-rhel9:1776231364"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1776171153"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1776168638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1776168580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1776168597"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1776168755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1776168548"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1776168731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1776172323"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1776170996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1776170085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1776169463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9:1776272700"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9-operator:1776168570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1776169866"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1776169550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1776140481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1776169045"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1776169220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1776131567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1776168778"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1776169657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hypershift-rhel9:1776168631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1776169271"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1776231376"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1776231752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1776231766"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-rhel9:1776231695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1776131777"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1776169412"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1776170255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1776170821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1776171076"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1776272397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1776170951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1776170749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1776170569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1776170491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1776170912"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1776170311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1776171922"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1776171907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1776169416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1776171002"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1776168565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1776169499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tests-rhel9:1776170901"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tools-rhel9:1776140622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1776168601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1776168580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1776168587"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1776168601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1775572657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1775564570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1775605177"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-service-rhel9-operator:1775606981"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1775572181"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1775564694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/egress-router-cni-rhel9:1775572299"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/frr-rhel9:1775602311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1775605722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1775565133"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1775605620"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1775604912"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/network-tools-rhel9:1775607479"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1775565249"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1775565065"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openstack-resource-controller-rhel9:1775606963"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1775606032"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1775572826"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1775606441"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1775572582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1775604573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1775564822"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1775557318"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1775557600"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1775602036"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1775602004"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1775557257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1775557692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1775557468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1775602036"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1775602060"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1775557684"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1775557242"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1775559294"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1775557341"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1775557282"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1775607663"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1775557298"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1775557287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1775565214"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1775577250"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-rhel9:1775563791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1775607238"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1775606727"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1775572199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1775573215"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1775564820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1775573046"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1775572490"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1775564722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1775604711"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1775604875"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1775557260"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1775564664"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1775606942"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1775605268"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1775564931"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1775572202"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1775573139"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1775604138"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1775604093"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1775605097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1775604716"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1775557255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1775557261"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1775606566"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1775604232"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1775573259"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1775605218"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1775606091"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1775572197"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1775605144"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1775606091"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1775606817"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1775606380"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1775606351"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9:1775630129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9-operator:1775606311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1775605056"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-coredns-rhel9:1775572853"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1775563218"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1775563629"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1775557766"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1775557312"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1775563562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1775564121"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1775563469"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1775564147"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1775563664"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1775564451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1775606800"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1775605796"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-etcd-rhel9:1775573039"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1775557397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1775562941"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1775557339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1775602042"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1775604398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1775557435"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hypershift-rhel9:1775573226"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1775572733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1775561999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1775566505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1775557304"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1775566494"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1775602040"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1775573055"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1775612304"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-rhel9:1775612266"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1775602311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1775604683"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1775563881"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1775564691"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1775604115"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1775565007"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1775604362"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1775557712"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1775557306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1775602000"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1775564642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1775607009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1775604341"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1775577192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1775604704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1775572688"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1775605333"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1775572927"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1775605900"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1775605545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-must-gather-rhel9:1775564698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1775605259"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1775605534"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1775557301"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1775557245"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1775605934"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1775572089"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1775605151"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1775604244"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1775604309"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1775572127"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1775564516"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1775604183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1775606187"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1775606809"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1775564624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1775606714"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1775605528"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1775604626"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1775564608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1775565149"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1775577164"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1775577363"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-pod-rhel9:1775572233"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1775563654"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1775601995"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1775563524"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1775562680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1775606841"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1775604108"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1775606783"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1775606725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9:1775604596"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1775606131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1775606843"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1775604108"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-telemeter-rhel9:1775604846"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tests-rhel9:1775578545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-thanos-rhel9:1775606385"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tools-rhel9:1775564250"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1775557272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1775557320"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1775557686"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1775557337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1775557272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1775557320"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1775557325"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1775557312"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1775606167"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7249",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1775604638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1772143108"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1772144253"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1772143861"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/azure-service-rhel9-operator:1772141804"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1772142576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1772144019"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/egress-router-cni-rhel9:1772143220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/frr-rhel9:1772143999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1772644085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1772644229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1772144695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1772141175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/network-tools-rhel9:1772595158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1772574958"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1772144029"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/openstack-resource-controller-rhel9:1772143448"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1772523439"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1772523362"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1772144004"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1772142177"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-ui-rhel9:1772138687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1772142349"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1772141184"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1772138481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1772138558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1772138512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1772138499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1772138530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1772138511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1772138620"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1772138530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1772138605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1772138480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1772138526"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1772138550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1772138504"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1772144786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1772655529"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1772144359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1772143306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1772142354"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1772524224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cli-rhel9:1772523269"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1772144014"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1772142857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1772144745"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1772141413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1772143467"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1772574867"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1772141541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1772144616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1772143505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1772142729"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1772144375"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1772143219"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1772141833"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1772142083"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1772141487"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1772144675"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1772141562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1772144499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1772144468"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1772142357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1772574880"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1772143585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1772142637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1772523242"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1772142186"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1772593591"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1772143567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1772143784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1772143458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1772141103"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1772144434"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1772141786"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1772143296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1772142921"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-console-rhel9:1772142269"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-console-rhel9-operator:1772141663"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1772142278"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-coredns-rhel9:1772142665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1772139730"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1772140894"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1772141273"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1772144699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1772142097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1772144027"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-snapshot-metadata-rhel9:1772144260"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1772144056"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1772142266"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1772142511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1772144436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1772143090"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1772142447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-etcd-rhel9:1772143126"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1772142217"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1772141921"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1772140710"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1772666832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1772143233"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1772141417"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-hypershift-rhel9:1772574935"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1772143941"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1772138681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1772138704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1772139730"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1772144828"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1772490783"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1772141241"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1772655389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-installer-rhel9:1772655272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1772593911"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1772143650"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1772141436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1772141284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1772142819"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1772142058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1772141707"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1772138490"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1772138544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1772142856"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1772141988"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1772143281"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1772608175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1772644163"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1772143907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1772144363"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1772144275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1772644153"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1772143637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1772144106"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-must-gather-rhel9:1772524101"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1772143661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1772144523"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1772138417"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1772138382"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1772141254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1772144025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1772574868"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1772144410"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1772142572"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1772144691"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1772142646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1772141699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1772666702"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1772143222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1772141559"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1772143082"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1772176727"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1772176665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1772143531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1772176674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1772467275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1772523424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-pod-rhel9:1772143045"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1772140895"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1772142175"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1772141519"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1772143131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1772143435"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1772433633"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1772144466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1772433634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-rhel9:1772143543"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1772433630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1772142820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1772142573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-telemeter-rhel9:1772141358"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-tests-rhel9:1772655350"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-thanos-rhel9:1772141288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-tools-rhel9:1772593622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1772138438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1772138413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1772138401"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1772138414"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1772138437"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1772138403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1772141084"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1772141210"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:3855",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/volume-data-source-validator-rhel9:1772141838"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:57546",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ansible-rhel9-operator:1787019838"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54603",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-ansible-rhel9-operator:1786526139"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.27",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6192",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.27::el9",
        "package": "devspaces/udi-rhel9:1774451954"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.28",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21772",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.28::el9",
        "package": "devspaces/udi-rhel9:1779829736"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3459",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/tempo-rhel9:1771843082"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9385",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/tempo-rhel9:1776435680"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.18",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3874",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.18::el8",
        "package": "openshift-gitops-1/dex-rhel8:1772438555"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.19",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3884",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.19::el8",
        "package": "openshift-gitops-1/dex-rhel8:1772445569"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/istio-cni-rhel8:1771992208"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/istio-rhel8-operator:1771992461"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/pilot-rhel8:1771992212"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3559",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/ratelimit-rhel8:1771992437"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5132",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/kiali-rhel8:1773059917"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8483",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/kiali-rhel8:1776191302"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3556",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el9",
        "package": "openshift-service-mesh/proxyv2-rhel9:1772083861"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5129",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/kiali-rhel9:1773059790"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1774214116"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1774006090"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1774068855"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5948",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1774294372"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5131",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/kiali-rhel9:1773060321"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1774037349"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1774037369"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1774244136"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5950",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1774293851"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5130",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/kiali-rhel9:1773060306"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1774206585"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1774206464"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1774114903"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5952",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1774294809"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5394",
        "cpe": "cpe:/a:redhat:openstack:17.1::el9",
        "package": "rhosp-rhel9/osp-director-agent:1773255177"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/sg-core-rhel9:1774974026"
      },
      {
        "product_name": "Red Hat Quay 3.1",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5665",
        "cpe": "cpe:/a:redhat:quay:3.10::el8",
        "package": "quay/quay-rhel8:1773971077"
      },
      {
        "product_name": "Red Hat Quay 3.12",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4942",
        "cpe": "cpe:/a:redhat:quay:3.12::el8",
        "package": "quay/quay-rhel8:1773771962"
      },
      {
        "product_name": "Red Hat Quay 3.15",
        "release_date": "2026-04-03T00:00:00Z",
        "advisory": "RHSA-2026:6568",
        "cpe": "cpe:/a:redhat:quay:3.15::el8",
        "package": "quay/quay-rhel8:1775169219"
      },
      {
        "product_name": "Red Hat Quay 3.16",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6497",
        "cpe": "cpe:/a:redhat:quay:3.16::el9",
        "package": "quay/quay-rhel9:1775069491"
      },
      {
        "product_name": "Red Hat Quay 3.16",
        "release_date": "2026-04-03T00:00:00Z",
        "advisory": "RHSA-2026:6567",
        "cpe": "cpe:/a:redhat:quay:3.16::el9",
        "package": "quay/quay-rhel9:1775169226"
      },
      {
        "product_name": "Red Hat Quay 3.9",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5168",
        "cpe": "cpe:/a:redhat:quay:3.9::el8",
        "package": "quay/quay-rhel8:1773936323"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14879",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/iop-vmaas-rhel9:1778082595"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10125",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/client-server-rhel9:1776339099"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5452",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/cosign-rhel9:1773309219"
      },
      {
        "product_name": "Red Hat Web Terminal 1.11",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10250",
        "cpe": "cpe:/a:redhat:webterminal:1.11::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1776966691"
      },
      {
        "product_name": "Red Hat Web Terminal 1.12",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10225",
        "cpe": "cpe:/a:redhat:webterminal:1.12::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1776959849"
      },
      {
        "product_name": "Red Hat Web Terminal 1.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8338",
        "cpe": "cpe:/a:redhat:webterminal:1.13::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1776197785"
      },
      {
        "product_name": "Red Hat Web Terminal 1.14",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8337",
        "cpe": "cpe:/a:redhat:webterminal:1.14::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1776199398"
      },
      {
        "product_name": "Red Hat Web Terminal 1.15",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8167",
        "cpe": "cpe:/a:redhat:webterminal:1.15::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1775672762"
      }
    ],
    "package_state": [
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "rhai/assisted-installer-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "build-of-trustee/trustee-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "openshift-sandboxed-containers/osc-monitor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Deployment Validation Operator",
        "fix_state": "Affected",
        "package_name": "dvo/deployment-validation-rhel8-operator",
        "cpe": "cpe:/a:redhat:deployment_validator_operator"
      },
      {
        "product_name": "ExternalDNS Operator",
        "fix_state": "Affected",
        "package_name": "edo/external-dns-rhel8",
        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
      },
      {
        "product_name": "ExternalDNS Operator",
        "fix_state": "Not affected",
        "package_name": "edo/external-dns-rhel9",
        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
      },
      {
        "product_name": "Fence Agents Remediation Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/fence-agents-remediation-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_far:0"
      },
      {
        "product_name": "Gatekeeper 3",
        "fix_state": "Under investigation",
        "package_name": "gatekeeper/gatekeeper-rhel9-operator",
        "cpe": "cpe:/a:redhat:gatekeeper:3"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Will not fix",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Will not fix",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Under investigation",
        "package_name": "lvms4/lvms-rhel9-operator",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Under investigation",
        "package_name": "lvms4/topolvm-rhel8",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Under investigation",
        "package_name": "lvms4/topolvm-rhel9",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/machine-deletion-remediation-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-cli-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "mirror registry for Red Hat OpenShift",
        "fix_state": "Will not fix",
        "package_name": "openshift/mirror-registry-rhel8",
        "cpe": "cpe:/a:redhat:mirror_registry:1"
      },
      {
        "product_name": "Multiarch Tuning Operator",
        "fix_state": "Affected",
        "package_name": "multiarch-tuning/multiarch-tuning-rhel9-operator",
        "cpe": "cpe:/a:redhat:multiarch_tuning_operator"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/node-healthcheck-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "Node Maintenance Operator",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/node-maintenance-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nmo:5"
      },
      {
        "product_name": "Node Maintenance Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/node-maintenance-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nmo:5"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "helm",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "ocp-tools-4/jenkins-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-jenkins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines-client",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "kn-workflow-plugin",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-plugin-event-sender-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-clients",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "rh-osbs/openshift-golang-builder",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Power monitoring for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-power-monitoring/kepler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_power_monitoring"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp2/3scale-rhel7-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Affected",
        "package_name": "3scale-amp2/3scale-rhel9-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp26/3scale-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp26/operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-tech-preview/authorino-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "rhcl-1/authorino-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat AMQ Broker 7",
        "fix_state": "Affected",
        "package_name": "amq7/amq-broker-rhel9-operator",
        "cpe": "cpe:/a:redhat:amq_broker:7"
      },
      {
        "product_name": "Red Hat AMQ Broker 7",
        "fix_state": "Not affected",
        "package_name": "golang-github-danielqsj-kafka_exporter",
        "cpe": "cpe:/a:redhat:amq_broker:7"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform/platform-operator-bundle",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "automation-gateway-proxy-openssl30",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "automation-gateway-proxy-openssl32",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3.11-galaxy-ng",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3.11-grpcio",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "python3.12-galaxy-ng",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "python3.12-grpcio",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3x-grpcio",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python-grpcio",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "receptor",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat build of Apache Camel - HawtIO 4",
        "fix_state": "Affected",
        "package_name": "hawtio-operator-container",
        "cpe": "cpe:/a:redhat:apache_camel_hawtio:4"
      },
      {
        "product_name": "Red Hat build of Apicurio Registry 2",
        "fix_state": "Will not fix",
        "package_name": "apicurio/apicurio-registry-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_registry:2"
      },
      {
        "product_name": "Red Hat build of Apicurio Registry 2",
        "fix_state": "Will not fix",
        "package_name": "apicurio/apicurio-registry-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_registry:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Affected",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Affected",
        "package_name": "rhel8/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Affected",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Affected",
        "package_name": "ceph",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Affected",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Affected",
        "package_name": "rhel8/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Affected",
        "package_name": "rhel9/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Affected",
        "package_name": "ceph",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Affected",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Affected",
        "package_name": "ceph",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Affected",
        "package_name": "rhceph/grafana-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Certification Program for Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "redhat-certification-preflight",
        "cpe": "cpe:/a:redhat:certifications:9"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Affected",
        "package_name": "rhcl-1/coredns-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "butane",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "gvisor-tap-vsock",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "ignition",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "rhel10/bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "host-metering",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "rhc",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "rhc-worker-script",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "weldr-client",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "butane",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "go-toolset",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "gvisor-tap-vsock",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "ignition",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "rhel9/bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "weldr-client",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Affected",
        "package_name": "jboss-webserver/jws-rhel9-operator",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Under investigation",
        "package_name": "rhoai/odh-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-maas-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Cluster Manager CLI",
        "fix_state": "Affected",
        "package_name": "ocm-cli-clients/ocm-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_cluster_manager_cli:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "butane",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "conmon-rs",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "cri-o",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "cri-tools",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "golang-github-prometheus-promu",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "ignition",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "microshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift-clients",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift-kuryr",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "ose-aws-ecr-image-credential-provider",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "ose-azure-acr-image-credential-provider",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "ose-gcp-gcr-image-credential-provider",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "rh-osbs/openshift-golang-builder",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Under investigation",
        "package_name": "odf4/cephcsi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Affected",
        "package_name": "rhosdt/tempo-rhel8",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Under investigation",
        "package_name": "openshift4-wincw/windows-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift on AWS",
        "fix_state": "Affected",
        "package_name": "rosa",
        "cpe": "cpe:/a:redhat:openshift_service_on_aws:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-api",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-api-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Under investigation",
        "package_name": "kubevirt",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "rh-osbs/openshift-golang-builder",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Will not fix",
        "package_name": "golang-github-infrawatch-apputils",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/osp-director-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "collectd-libpod-stats",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Affected",
        "package_name": "golang-github-infrawatch-apputils",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/clair-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "satellite:el8/yggdrasil-worker-forwarder",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Service Interconnect 1",
        "fix_state": "Not affected",
        "package_name": "skupper-cli",
        "cpe": "cpe:/a:redhat:service_interconnect:1"
      },
      {
        "product_name": "Red Hat Service Interconnect 2",
        "fix_state": "Not affected",
        "package_name": "skupper-cli",
        "cpe": "cpe:/a:redhat:service_interconnect:2"
      },
      {
        "product_name": "Security Profiles Operator",
        "fix_state": "Under investigation",
        "package_name": "compliance/openshift-selinuxd-rhel8",
        "cpe": "cpe:/a:redhat:openshift_security_profiles_operator:1"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Under investigation",
        "package_name": "stf/sg-core-rhel9",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-68121\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-68121\nhttps://go.dev/cl/737700\nhttps://go.dev/issue/77217\nhttps://groups.google.com/g/golang-announce/c/K09ubi9FQFk\nhttps://pkg.go.dev/vuln/GO-2026-4337"
    ],
    "name": "CVE-2025-68121",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-16T18:10:54Z",
    "bugzilla": {
      "description": "filelock: filelock: Time-of-Check-Time-of-Use (TOCTOU) race condition and symlink attack allows arbitrary file corruption or truncation",
      "id": "2422884",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2422884"
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-367",
    "details": [
      "filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock checks if a file exists before opening it with O_TRUNC. An attacker can create a symlink pointing to a victim file in the time gap between the check and open, causing os.open() to follow the symlink and truncate the target file. All users of filelock on Unix, Linux, macOS, and Windows systems are impacted. The vulnerability cascades to dependent libraries. The attack requires local filesystem access and ability to create symlinks (standard user permissions on Unix; Developer Mode on Windows 10+). Exploitation succeeds within 1-3 attempts when lock file paths are predictable. The issue is fixed in version 3.20.1. If immediate upgrade is not possible, use SoftFileLock instead of UnixFileLock/WindowsFileLock (note: different locking semantics, may not be suitable for all use cases); ensure lock file directories have restrictive permissions (chmod 0700) to prevent untrusted users from creating symlinks; and/or monitor lock file directories for suspicious symlinks before running trusted applications. These workarounds provide only partial mitigation. The race condition remains exploitable. Upgrading to version 3.20.1 is strongly recommended.",
      "A flaw was found in filelock. This vulnerability allows local attackers to corrupt or truncate arbitrary user files via a Time-of-Check-Time-of-Use (TOCTOU) race condition and symlink attacks."
    ],
    "statement": "This vulnerability is rated Moderate for Red Hat because it is a Time-of-Check-Time-of-Use (TOCTOU) race condition in the `filelock` library that allows a local attacker with low privileges to truncate or corrupt arbitrary user files via symlink attacks. Exploitation requires local filesystem access and the ability to create symlinks, which are standard user permissions on Unix-like systems. The impact is limited to applications utilizing affected versions of `filelock` that create lock files in predictable, attacker-writable locations.",
    "package_state": [
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Fix deferred",
        "package_name": "rhmtc/openshift-migration-hook-runner-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-cni-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-pilot-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-sail-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh-tech-preview/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis-preview/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-dellemc-openmanage-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/aap-cloud-metrics-collector-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ansible-dev-tools-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-cloud-services-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ansible-dev-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/mcp-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ansible-devspaces-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-aws-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-azure-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-azure-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-gcp-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-intel-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/instructlab-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/instructlab-intel-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/instructlab-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/disk-image-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-nlp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-tgis-serving-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-data-science-pipelines-operator-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-data-science-pipelines-operator-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-guardrails-detector-huggingface-runtime-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ta-lmes-job-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda121-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda124-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda128-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-ragas-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/dashboard-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/devspaces-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/udi-base-rhel10",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/udi-base-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/udi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso-operators/ee-openstack-ansible-ee-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-host-inventory-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-insights-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-puptoo-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vulnerability-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-yuptoo-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Fix deferred",
        "package_name": "rhtas/model-transparency-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-68146\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-68146\nhttps://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e\nhttps://github.com/tox-dev/filelock/pull/461\nhttps://github.com/tox-dev/filelock/releases/tag/3.20.1\nhttps://github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f"
    ],
    "name": "CVE-2025-68146",
    "mitigation": {
      "value": "Ensure lock file directories used by applications employing filelock have restrictive permissions, such as chmod 0700, to prevent untrusted users from creating symlinks. Additionally, monitor these directories for suspicious symlinks before executing trusted applications. Applying these permission changes may require a service reload or restart.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-01-27T00:00:00Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter",
      "id": "2430380",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
    },
    "cvss3": {
      "cvss3_base_score": "4.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "Issue summary: Writing large, newline-free data into a BIO chain using the\nline-buffering filter where the next BIO performs short writes can trigger\na heap-based out-of-bounds write.\nImpact summary: This out-of-bounds write can cause memory corruption which\ntypically results in a crash, leading to Denial of Service for an application.\nThe line-buffering BIO filter (BIO_f_linebuffer) is not used by default in\nTLS/SSL data paths. In OpenSSL command-line applications, it is typically\nonly pushed onto stdout/stderr on VMS systems. Third-party applications that\nexplicitly use this filter with a BIO chain that can short-write and that\nwrite large, newline-free data influenced by an attacker would be affected.\nHowever, the circumstances where this could happen are unlikely to be under\nattacker control, and BIO_f_linebuffer is unlikely to be handling non-curated\ndata controlled by an attacker. For that reason the issue was assessed as\nLow severity.\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the BIO implementation is outside the OpenSSL FIPS module boundary.\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
      "A flaw was found in OpenSSL. This vulnerability involves an out-of-bounds write in the line-buffering BIO filter, which can lead to memory corruption. While exploitation is unlikely to be under direct attacker control, a successful attack could cause an application to crash, resulting in a Denial of Service (DoS)."
    ],
    "statement": "This vulnerability is rated Low for Red Hat. The `BIO_f_linebuffer` filter, where this heap out-of-bounds write occurs, is not used by default in TLS/SSL data paths within Red Hat products. Exploitation requires third-party applications to explicitly use this filter with a BIO chain that can short-write and process large, newline-free data influenced by an attacker, which is an unlikely scenario under attacker control. Red Hat FIPS modules are not affected by this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1472",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssl-1:3.5.1-7.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Cost Management Metrics Operator 4",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3228",
        "cpe": "cpe:/a:redhat:cost_management:4::el9",
        "package": "costmanagement/costmanagement-metrics-rhel9-operator:1770836349"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1769104765"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1769111774"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7261",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssl-main-3.5.6-0.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2485",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1770740405"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2563",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1770646925"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1773670073"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1773672059"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1773670137"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-68160\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-68160"
    ],
    "name": "CVE-2025-68160",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-12T17:31:49Z",
    "bugzilla": {
      "description": "avahi: Avahi: Denial of Service via D-Bus record browsers with AVAHI_LOOKUP_USE_WIDE_AREA flag",
      "id": "2428713",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2428713"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-617",
    "details": [
      "Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling\nthe RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.",
      "A flaw was found in Avahi, a system that facilitates service discovery on a local network. An unprivileged local user can exploit this vulnerability by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can lead to a Denial of Service (DoS) by crashing the avahi-daemon, making the service unavailable."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11316",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "avahi-main-0.9~rc4-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-68276\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-68276\nhttps://github.com/avahi/avahi/commit/ede7048475c5d47d53890e3bc1350dda8e0b3688\nhttps://github.com/avahi/avahi/pull/806\nhttps://github.com/avahi/avahi/security/advisories/GHSA-mhf3-865v-g5rc"
    ],
    "name": "CVE-2025-68276",
    "csaw": false
  },
  {
    "public_date": "2025-12-22T00:00:00Z",
    "bugzilla": {
      "description": "kernel: iio: accel: bmc150: Fix irq assumption regression",
      "id": "2424334",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2424334"
    },
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\niio: accel: bmc150: Fix irq assumption regression\nThe code in bmc150-accel-core.c unconditionally calls\nbmc150_accel_set_interrupt() in the iio_buffer_setup_ops,\nsuch as on the runtime PM resume path giving a kernel\nsplat like this if the device has no interrupts:\nUnable to handle kernel NULL pointer dereference at virtual\naddress 00000001 when read\nPC is at bmc150_accel_set_interrupt+0x98/0x194\nLR is at __pm_runtime_resume+0x5c/0x64\n(...)\nCall trace:\nbmc150_accel_set_interrupt from bmc150_accel_buffer_postenable+0x40/0x108\nbmc150_accel_buffer_postenable from __iio_update_buffers+0xbe0/0xcbc\n__iio_update_buffers from enable_store+0x84/0xc8\nenable_store from kernfs_fop_write_iter+0x154/0x1b4\nThis bug seems to have been in the driver since the beginning,\nbut it only manifests recently, I do not know why.\nStore the IRQ number in the state struct, as this is a common\npattern in other drivers, then use this to determine if we have\nIRQ support or not."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-68330\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-68330\nhttps://lore.kernel.org/linux-cve-announce/2025122218-CVE-2025-68330-94b5@gregkh/T"
    ],
    "name": "CVE-2025-68330",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-12T17:38:10Z",
    "bugzilla": {
      "description": "avahi: Avahi: Denial of Service via crafted mDNS/DNS-SD announcements",
      "id": "2428714",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2428714"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-617",
    "details": [
      "Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.",
      "A flaw was found in Avahi. A remote attacker can cause a Denial of Service (DoS) by sending specially crafted unsolicited announcements containing CNAME resource records. These records, when pointing to other resource records with short Time-To-Live (TTL) values, can lead to the `avahi-daemon` crashing once they expire. This vulnerability impacts the availability of services relying on Avahi's service discovery."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11316",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "avahi-main-0.9~rc4-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-68468\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-68468\nhttps://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a\nhttps://github.com/avahi/avahi/issues/683\nhttps://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"
    ],
    "name": "CVE-2025-68468",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-12T17:39:57Z",
    "bugzilla": {
      "description": "avahi: Avahi: Denial of Service via unsolicited CNAME announcements",
      "id": "2428717",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2428717"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-617",
    "details": [
      "Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.",
      "A flaw was found in Avahi, a system that enables devices to discover services on a local network using the mDNS/DNS-SD (Multicast Domain Name System/DNS-based Service Discovery) protocols. A remote attacker can exploit this by sending two specific network messages, known as unsolicited announcements with CNAME resource records, within a two-second timeframe. This action can cause the `avahi-daemon` process to crash, leading to a Denial of Service (DoS) for the affected system."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11316",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "avahi-main-0.9~rc4-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-68471\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-68471\nhttps://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1\nhttps://github.com/avahi/avahi/issues/678\nhttps://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"
    ],
    "name": "CVE-2025-68471",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-01-05T23:16:19Z",
    "bugzilla": {
      "description": "aiohttp: aiohttp: Request smuggling vulnerability via non-ASCII decimals in Range header",
      "id": "2427253",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2427253"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-444",
    "details": [
      "AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.",
      "A flaw was found in aiohttp, an asynchronous HTTP client/server framework. The parser logic allows non-ASCII decimal characters in the HTTP Range header. This could potentially enable a remote attacker to exploit a request smuggling vulnerability, leading to the bypass of security controls or unauthorized information access."
    ],
    "statement": "This vulnerability is rated Low for Red Hat products as it affects components utilizing the aiohttp framework, including Red Hat AI Inference Server, Red Hat Ansible Automation Platform, Migration Toolkit for Containers, OpenShift Lightspeed, Hosted OpenShift Clusters, OpenShift Service Mesh, Red Hat Enterprise Linux AI, Red Hat OpenShift AI (RHOAI), and Red Hat Satellite. The flaw in aiohttp's parser logic could enable request smuggling if non-ASCII decimals are present in the HTTP Range header, potentially bypassing security controls or allowing unauthorized information access.",
    "package_state": [
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Fix deferred",
        "package_name": "rhmtc/openshift-migration-hook-runner-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis-preview/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-dellemc-openmanage-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/hub-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/aap-cloud-metrics-collector-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ansible-dev-tools-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-cloud-services-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/hub-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ansible-dev-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/mcp-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ansible-devspaces-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-nlp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-tgis-serving-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ta-lmes-job-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda121-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda124-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda128-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-ragas-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-insights-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vulnerability-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-69225\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-69225\nhttps://github.com/aio-libs/aiohttp/commit/c7b7a044f88c71cefda95ec75cdcfaa4792b3b96\nhttps://github.com/aio-libs/aiohttp/security/advisories/GHSA-mqqc-3gqh-h2x8"
    ],
    "name": "CVE-2025-69225",
    "mitigation": {
      "value": "No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-05T23:19:31Z",
    "bugzilla": {
      "description": "aiohttp: aiohttp: Denial of Service via specially crafted POST request",
      "id": "2427256",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2427256"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-835",
    "details": [
      "AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS attack when processing a POST body. If optimizations are enabled (-O or PYTHONOPTIMIZE=1), and the application includes a handler that uses the Request.post() method, then an attacker may be able to execute a DoS attack with a specially crafted message. This issue is fixed in version 3.13.3.",
      "A flaw was found in aiohttp, an asynchronous HTTP client/server framework for Python. A remote attacker could exploit this vulnerability by sending a specially crafted POST request to an application using the Request.post() method, provided that Python optimizations are enabled. This could lead to an infinite loop, resulting in a Denial of Service (DoS) attack, making the affected application unavailable."
    ],
    "statement": "This vulnerability is rated Moderate for Red Hat products as it can lead to a Denial of Service (DoS) in applications utilizing the `aiohttp` library. Exploitation requires Python optimizations to be explicitly enabled (e.g., via `-O` or `PYTHONOPTIMIZE=1`) and the application to process POST requests using the `Request.post()` method. Red Hat products are affected if they meet these specific configuration and usage criteria.",
    "affected_release": [
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5809",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1774351144"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6761",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1774547384"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6762",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1775252598"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13553",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "ansible-automation-platform-25/lightspeed-rhel8:1777403872"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-chatbot-rhel9:1777398576"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-rhel9:1777387242"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59155",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-rhel9:1787244079"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59155",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/mcp-tools-rhel9:1787219369"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Execution Environments 2.18",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55853",
        "cpe": "cpe:/a:redhat:ansible_core:2.18::el8",
        "package": "ansible-automation-platform/ee-minimal-rhel8:1786971288"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Execution Environments 2.18",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55852",
        "cpe": "cpe:/a:redhat:ansible_core:2.18::el9",
        "package": "ansible-automation-platform/ee-minimal-rhel9:1786942232"
      },
      {
        "product_name": "Red Hat Migration Toolkit 1.8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41928",
        "cpe": "cpe:/a:redhat:rhmt:1.8::el8",
        "package": "rhmtc/openshift-migration-hook-runner-rhel8:1783931722"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-caikit-tgis-serving-rhel9:1776247907"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-feature-server-rhel9:1776338381"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-model-registry-job-async-upload-rhel9:1776349389"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-vllm-cpu-rhel9:1776259063"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-caikit-nlp-rhel9:1780069094"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3782",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-vllm-gaudi-rhel9:1772093278"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-vllm-cuda-rhel9:1783998774"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-vllm-rocm-rhel9:1783998857"
      }
    ],
    "package_state": [
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/ee-dellemc-openmanage-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-24/hub-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-24/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/aap-cloud-metrics-collector-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/ansible-dev-tools-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/de-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/ee-cloud-services-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/hub-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/ansible-dev-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-tech-preview/ansible-devspaces-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-registry-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ta-lmes-job-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-cuda121-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-cuda124-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-training-cuda128-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-rocm62-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-rocm62-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-training-rocm64-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-ragas-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "satellite/iop-insights-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "satellite/iop-vulnerability-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-69227\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-69227\nhttps://github.com/aio-libs/aiohttp/commit/bc1319ec3cbff9438a758951a30907b072561259\nhttps://github.com/aio-libs/aiohttp/security/advisories/GHSA-jj3x-wxrx-4x23"
    ],
    "name": "CVE-2025-69227",
    "mitigation": {
      "value": "No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-05T23:30:33Z",
    "bugzilla": {
      "description": "aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request",
      "id": "2427254",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2427254"
    },
    "cvss3": {
      "cvss3_base_score": "6.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.",
      "A flaw was found in aiohttp. A remote attacker can craft a malicious request that, when processed by an aiohttp server using the `Request.post()` method, causes the server's memory to fill uncontrollably. This can lead to a Denial of Service (DoS) by freezing the server, making it unavailable to legitimate users."
    ],
    "statement": "This vulnerability is rated Moderate for Red Hat products. A flaw in aiohttp allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted POST request to an aiohttp server that utilizes the `Request.post()` method. This can lead to uncontrolled memory consumption, freezing the server and making the server unavailable.",
    "affected_release": [
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5809",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1774351144"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6761",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1774547384"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6762",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1775252598"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-chatbot-rhel9:1777398576"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-rhel9:1777387242"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59155",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-rhel9:1787244079"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Execution Environments 2.18",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55853",
        "cpe": "cpe:/a:redhat:ansible_core:2.18::el8",
        "package": "ansible-automation-platform/ee-minimal-rhel8:1786971288"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Execution Environments 2.18",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55852",
        "cpe": "cpe:/a:redhat:ansible_core:2.18::el9",
        "package": "ansible-automation-platform/ee-minimal-rhel9:1786942232"
      },
      {
        "product_name": "Red Hat Migration Toolkit 1.8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41928",
        "cpe": "cpe:/a:redhat:rhmt:1.8::el8",
        "package": "rhmtc/openshift-migration-hook-runner-rhel8:1783931722"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-caikit-tgis-serving-rhel9:1776247907"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-feature-server-rhel9:1776338381"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-model-registry-job-async-upload-rhel9:1776349389"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-vllm-cpu-rhel9:1776259063"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-caikit-nlp-rhel9:1780069094"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-03-04T00:00:00Z",
        "advisory": "RHSA-2026:3782",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-vllm-gaudi-rhel9:1772093278"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-vllm-cuda-rhel9:1783998774"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-vllm-rocm-rhel9:1783998857"
      }
    ],
    "package_state": [
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/ee-dellemc-openmanage-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-24/hub-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-24/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/de-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/hub-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/ansible-dev-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-mcp-tools-container",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-registry-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ta-lmes-job-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-cuda121-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-cuda124-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-training-cuda128-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-rocm62-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-rocm62-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-training-rocm64-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-ragas-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "satellite/iop-insights-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "satellite/iop-vulnerability-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-69228\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-69228\nhttps://github.com/aio-libs/aiohttp/commit/b7dbd35375aedbcd712cbae8ad513d56d11cce60\nhttps://github.com/aio-libs/aiohttp/security/advisories/GHSA-6jhg-hg63-jvvf"
    ],
    "name": "CVE-2025-69228",
    "mitigation": {
      "value": "No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-05T23:37:52Z",
    "bugzilla": {
      "description": "aiohttp: AIOHTTP: Denial of Service via excessive CPU usage in chunked message handling",
      "id": "2427257",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2427257"
    },
    "cvss3": {
      "cvss3_base_score": "5.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-770",
    "details": [
      "AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks. If an application makes use of the request.read() method in an endpoint, it may be possible for an attacker to cause the server to spend a moderate amount of blocking CPU time (e.g. 1 second) while processing the request. This could potentially lead to DoS as the server would be unable to handle other requests during that time. This issue is fixed in version 3.13.3.",
      "A flaw was found in aiohttp, an asynchronous HTTP client/server framework for asyncio and Python. An attacker can exploit this vulnerability by sending a large number of chunks in a message. This can lead to excessive blocking CPU usage when the application processes the request, potentially causing a Denial of Service (DoS) as the server becomes unresponsive to other requests."
    ],
    "statement": "This vulnerability is rated Moderate for Red Hat products. A flaw in the `aiohttp` library, used across various Red Hat offerings, allows an unauthenticated attacker to cause a Denial of Service. By sending a large number of chunks in an HTTP message, an attacker can trigger excessive CPU usage, rendering the affected service temporarily unresponsive.",
    "package_state": [
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Fix deferred",
        "package_name": "rhmtc/openshift-migration-hook-runner-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis-preview/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-dellemc-openmanage-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/hub-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/aap-cloud-metrics-collector-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ansible-dev-tools-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-cloud-services-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/hub-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ansible-dev-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/mcp-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ansible-devspaces-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-nlp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-tgis-serving-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ta-lmes-job-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda121-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda124-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda128-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-ragas-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-insights-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vulnerability-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-69229\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-69229\nhttps://github.com/aio-libs/aiohttp/commit/4ed97a4e46eaf61bd0f05063245f613469700229\nhttps://github.com/aio-libs/aiohttp/commit/dc3170b56904bdf814228fae70a5501a42a6c712\nhttps://github.com/aio-libs/aiohttp/security/advisories/GHSA-g84x-mcqj-x9qq"
    ],
    "name": "CVE-2025-69229",
    "mitigation": {
      "value": "No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-12-31T05:50:07Z",
    "bugzilla": {
      "description": "libsodium: pynacl: libsodium: Improper validation of elliptic curve points could lead to data integrity or information disclosure.",
      "id": "2426416",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2426416"
    },
    "cvss3": {
      "cvss3_base_score": "4.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-184",
    "details": [
      "libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.",
      "A flaw was found in libsodium and pynacl. When processing untrusted data in specific cryptographic operations, the library's crypto_core_ed25519_is_valid_point function incorrectly validates elliptic curve points. This improper validation could allow an attacker to bypass security checks, potentially leading to a compromise of data integrity or the disclosure of sensitive information in certain custom cryptographic implementations."
    ],
    "statement": "This vulnerability is rated Moderate for Red Hat products as it primarily affects atypical use cases involving custom cryptographic implementations or untrusted data processing with `crypto_core_ed25519_is_valid_point`. Standard libsodium deployments are not expected to be impacted by this flaw.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7369",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libsodium-main-1.0.22-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Fix deferred",
        "package_name": "rhmtc/openshift-migration-hook-runner-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/grafana-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/aap-cloud-metrics-collector-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/aap-cloud-metrics-collector-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ansible-dev-tools-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-cloud-services-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-dellemc-openmanage-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ansible-dev-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/mcp-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ansible-devspaces-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Fix deferred",
        "package_name": "rhdh/rhdh-hub-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "libsodium",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-ceilometer-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-ceilometer-central",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-ceilometer-compute",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-ceilometer-ipmi",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-ceilometer-notification",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-cinder-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-cinder-backup",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-cinder-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-cinder-scheduler",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-cinder-volume",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-heat-all",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-heat-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-heat-api-cfn",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-heat-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-heat-engine",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-ironic-neutron-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-manila-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-manila-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-manila-scheduler",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-manila-share",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-mariadb",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-mistral-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-mistral-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-mistral-engine",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-mistral-event-engine",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-mistral-executor",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-neutron-agent-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-neutron-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-neutron-dhcp-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-neutron-l3-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-neutron-metadata-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-neutron-metadata-agent-ovn",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-neutron-openvswitch-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-neutron-server",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-neutron-server-ovn",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-neutron-sriov-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-nova-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-nova-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-nova-compute",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-nova-compute-ironic",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-nova-conductor",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-nova-libvirt",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-nova-novncproxy",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-nova-scheduler",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-octavia-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-panko-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-swift-proxy-server",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-tempest",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-tripleoclient",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "libsodium",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-nova-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-nova-libvirt",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-tripleoclient",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ceilometer-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ceilometer-central",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ceilometer-compute",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ceilometer-ipmi",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ceilometer-notification",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-cinder-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-cinder-backup",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-cinder-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-cinder-scheduler",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-cinder-volume",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-heat-all",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-heat-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-heat-api-cfn",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-heat-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-heat-engine",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ironic-neutron-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-manila-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-manila-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-manila-scheduler",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-manila-share",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-mariadb",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-agent-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-dhcp-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-l3-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-metadata-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-metadata-agent-ovn",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-openvswitch-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-server",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-sriov-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-base",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-compute",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-compute-ironic",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-conductor",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-libvirt",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-novncproxy",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-nova-scheduler",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-octavia-api",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-ovn-bgp-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-swift-proxy-server",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-tempest",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-tripleoclient",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "libsodium",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-cinder-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-cinder-backup-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-cinder-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-cinder-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-cinder-volume-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-heat-api-cfn-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-heat-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-heat-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-heat-engine-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-ironic-neutron-agent-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-manila-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-manila-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-manila-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-manila-share-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-neutron-agent-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-neutron-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-neutron-dhcp-agent-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-neutron-metadata-agent-ovn-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-neutron-ovn-agent-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-neutron-server-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-neutron-sriov-agent-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-nova-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-nova-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-nova-compute-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-nova-conductor-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-nova-novncproxy-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-nova-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-octavia-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-ovn-bgp-agent-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-tempest-all-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso/openstack-tempest-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso-operators/ee-openstack-ansible-ee-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "libsodium",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite:el8/libsodium",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-insights-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-69277\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-69277\nhttps://00f.net/2025/12/30/libsodium-vulnerability/\nhttps://github.com/jedisct1/libsodium/commit/ad3004ec8731730e93fcfbbc824e67eadc1c1bae\nhttps://ianix.com/pub/ed25519-deployment.html\nhttps://news.ycombinator.com/item?id=46435614"
    ],
    "name": "CVE-2025-69277",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-01-27T00:00:00Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls",
      "id": "2430381",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
    },
    "cvss3": {
      "cvss3_base_score": "4.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-325",
    "details": [
      "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
      "A flaw was found in OpenSSL. When applications directly call the low-level CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions with non-block-aligned lengths in a single call on hardware-accelerated builds, the trailing 1-15 bytes of a message may be exposed in cleartext. These exposed bytes are not covered by the authentication tag, allowing an attacker to read or tamper with them without detection."
    ],
    "statement": "This vulnerability is rated Low for Red Hat products. In the Red Hat context, impact is limited because typical OpenSSL consumers using higher-level EVP APIs are not affected. The flaw only manifests when applications directly call low-level CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions with non-block-aligned lengths in hardware-accelerated builds. Additionally, TLS does not use OCB ciphersuites, and FIPS modules are not affected.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1472",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssl-1:3.5.1-7.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Cost Management Metrics Operator 4",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3228",
        "cpe": "cpe:/a:redhat:cost_management:4::el9",
        "package": "costmanagement/costmanagement-metrics-rhel9-operator:1770836349"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1769104765"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1769111774"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7261",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssl-main-3.5.6-0.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2485",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1770740405"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2563",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1770646925"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1773670073"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1773672059"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1773670137"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-69418\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-69418"
    ],
    "name": "CVE-2025-69418",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-27T00:00:00Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing",
      "id": "2430386",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously\ncrafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing\nnon-ASCII BMP code point can trigger a one byte write before the allocated\nbuffer.\nImpact summary: The out-of-bounds write can cause a memory corruption\nwhich can have various consequences including a Denial of Service.\nThe OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12\nBMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes,\nthe helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16\nsource byte count as the destination buffer capacity to UTF8_putc(). For BMP\ncode points above U+07FF, UTF-8 requires three bytes, but the forwarded\ncapacity can be just two bytes. UTF8_putc() then returns -1, and this negative\nvalue is added to the output length without validation, causing the\nlength to become negative. The subsequent trailing NUL byte is then written\nat a negative offset, causing write outside of heap allocated buffer.\nThe vulnerability is reachable via the public PKCS12_get_friendlyname() API\nwhen parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a\ndifferent code path that avoids this issue, PKCS12_get_friendlyname() directly\ninvokes the vulnerable function. Exploitation requires an attacker to provide\na malicious PKCS#12 file to be parsed by the application and the attacker\ncan just trigger a one zero byte write before the allocated buffer.\nFor that reason the issue was assessed as Low severity according to our\nSecurity Policy.\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\nOpenSSL 1.0.2 is not affected by this issue.",
      "A flaw was found in OpenSSL. When processing a specially crafted PKCS#12 (Personal Information Exchange Syntax Standard) file, a remote attacker can exploit an out-of-bounds write vulnerability. This issue, occurring within the OPENSSL_uni2utf8() function, leads to memory corruption by writing data beyond its allocated buffer. Successful exploitation could result in a denial of service or potentially allow for arbitrary code execution."
    ],
    "statement": "This vulnerability is rated Moderate for Red Hat. An out-of-bounds write in OpenSSL's PKCS12_get_friendlyname() function can lead to denial of service or arbitrary code execution. Exploitation requires an application to parse a specially crafted malicious PKCS#12 file. Red Hat FIPS modules are not affected as the PKCS#12 implementation is outside the FIPS module boundary.",
    "affected_release": [
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-apr-util-0:1.6.3-4.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-httpd-0:2.4.62-11.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-mod_http2-0:2.0.29-8.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-mod_jk-0:1.2.50-12.redhat_1.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-mod_md-1:2.4.28-13.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-mod_proxy_cluster-0:1.3.22-7.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-mod_security-0:2.9.6-14.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-apr-util-0:1.6.3-4.el7jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-curl-0:8.11.0-4.el7jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-httpd-0:2.4.62-11.el7jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-mod_http2-0:2.0.29-8.el7jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-mod_jk-0:1.2.50-12.redhat_1.el7jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-mod_md-1:2.4.28-13.el7jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-mod_proxy_cluster-0:1.3.22-7.el7jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-mod_security-0:2.9.6-14.el7jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-openssl-chil-0:1.0.0-25.el7jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-openssl-pkcs11-0:0.4.12-5.el7jbcs"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1472",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssl-1:3.5.1-7.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1496",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "openssl-1:3.2.2-16.el10_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3042",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "openssl-1:1.1.1k-15.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4214",
        "cpe": "cpe:/o:redhat:rhel_aus:8.2",
        "package": "openssl-1:1.1.1c-21.el8_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4163",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "openssl-1:1.1.1g-18.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4163",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "openssl-1:1.1.1g-18.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3437",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "openssl-1:1.1.1k-15.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3437",
        "cpe": "cpe:/o:redhat:rhel_tus:8.6",
        "package": "openssl-1:1.1.1k-15.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3437",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.6",
        "package": "openssl-1:1.1.1k-15.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3364",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "openssl-1:1.1.1k-15.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3364",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "openssl-1:1.1.1k-15.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19187",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "compat-openssl11-1:1.1.1k-5.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4472",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "compat-openssl11-1:1.1.1k-5.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1733",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "openssl-1:3.0.1-46.el9_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5214",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "compat-openssl11-1:1.1.1k-4.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-01-29T00:00:00Z",
        "advisory": "RHSA-2026:1594",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "openssl-1:3.0.7-18.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5217",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "compat-openssl11-1:1.1.1k-4.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-29T00:00:00Z",
        "advisory": "RHSA-2026:1519",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "openssl-1:3.0.7-29.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4825",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "compat-openssl11-1:1.1.1k-5.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1503",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "openssl-1:3.2.2-7.el9_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4824",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "compat-openssl11-1:1.1.1k-5.el9_6.2"
      },
      {
        "product_name": "Red Hat JBoss Core Services 2.4.62.SP3",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2995",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "openssl"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3861",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202603041314-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7239",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202604080111-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:15087",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202605060243-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14773",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202605060220-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:5873",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202603231244-0"
      },
      {
        "product_name": "Cost Management Metrics Operator 4",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3228",
        "cpe": "cpe:/a:redhat:cost_management:4::el9",
        "package": "costmanagement/costmanagement-metrics-rhel9-operator:1770836349"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1769104765"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1769111774"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7261",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssl-main-3.5.6-0.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2485",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1770740405"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2563",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1770646925"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1773670073"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1773672059"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1773670137"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-69419\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-69419"
    ],
    "name": "CVE-2025-69419",
    "mitigation": {
      "value": "To mitigate this vulnerability, Red Hat recommends avoiding the processing of PKCS#12 files from untrusted or unverified sources. Applications that use the `PKCS12_get_friendlyname()` API should ensure that PKCS#12 files are only processed if they originate from trusted entities. Restricting the input sources for PKCS#12 files can significantly reduce the attack surface for this flaw.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-01-27T00:00:00Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Denial of Service via malformed TimeStamp Response",
      "id": "2430388",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-843",
    "details": [
      "Issue summary: A type confusion vulnerability exists in the TimeStamp Response\nverification code where an ASN1_TYPE union member is accessed without first\nvalidating the type, causing an invalid or NULL pointer dereference when\nprocessing a malformed TimeStamp Response file.\nImpact summary: An application calling TS_RESP_verify_response() with a\nmalformed TimeStamp Response can be caused to dereference an invalid or\nNULL pointer when reading, resulting in a Denial of Service.\nThe functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2()\naccess the signing cert attribute value without validating its type.\nWhen the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory\nthrough the ASN1_TYPE union, causing a crash.\nExploiting this vulnerability requires an attacker to provide a malformed\nTimeStamp Response to an application that verifies timestamp responses. The\nTimeStamp protocol (RFC 3161) is not widely used and the impact of the\nexploit is just a Denial of Service. For these reasons the issue was\nassessed as Low severity.\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the TimeStamp Response implementation is outside the OpenSSL FIPS module\nboundary.\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\nOpenSSL 1.0.2 is not affected by this issue.",
      "A flaw was found in OpenSSL. A type confusion vulnerability exists in the TimeStamp Response verification code, where an ASN1_TYPE union member is accessed without proper type validation. A remote attacker can exploit this by providing a malformed TimeStamp Response to an application that verifies timestamp responses. This can lead to an invalid or NULL pointer dereference, resulting in a Denial of Service (DoS) due to an application crash."
    ],
    "statement": "This vulnerability is rated Low for Red Hat products. A type confusion flaw in the TimeStamp Response verification code can lead to a Denial of Service when processing a specially crafted TimeStamp Response. Exploitation requires an application to call `TS_RESP_verify_response()` with a malformed response, and the TimeStamp protocol (RFC 3161) is not widely used. Red Hat FIPS modules are not affected as the TimeStamp Response implementation is outside the FIPS module boundary.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1472",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssl-1:3.5.1-7.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Cost Management Metrics Operator 4",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3228",
        "cpe": "cpe:/a:redhat:cost_management:4::el9",
        "package": "costmanagement/costmanagement-metrics-rhel9-operator:1770836349"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1769104765"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1769111774"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7261",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssl-main-3.5.6-0.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2485",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1770740405"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2563",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1770646925"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1773670073"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1773672059"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1773670137"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-69420\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-69420"
    ],
    "name": "CVE-2025-69420",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-01-27T00:00:00Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing",
      "id": "2430387",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer\ndereference in the PKCS12_item_decrypt_d2i_ex() function.\nImpact summary: A NULL pointer dereference can trigger a crash which leads to\nDenial of Service for an application processing PKCS#12 files.\nThe PKCS12_item_decrypt_d2i_ex() function does not check whether the oct\nparameter is NULL before dereferencing it. When called from\nPKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can\nbe NULL, causing a crash. The vulnerability is limited to Denial of Service\nand cannot be escalated to achieve code execution or memory disclosure.\nExploiting this issue requires an attacker to provide a malformed PKCS#12 file\nto an application that processes it. For that reason the issue was assessed as\nLow severity according to our Security Policy.\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
      "A flaw was found in OpenSSL. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by providing a specially crafted, malformed PKCS#12 file to an application that processes it. The flaw occurs due to a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function when handling the malformed file, leading to an application crash."
    ],
    "statement": "This vulnerability is rated Low for Red Hat because it requires an application to process a specially crafted, malformed PKCS#12 file, leading to a Denial of Service. The vulnerability is limited to a crash and cannot be escalated to achieve code execution or memory disclosure. Red Hat FIPS modules are not affected as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1472",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssl-1:3.5.1-7.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Cost Management Metrics Operator 4",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3228",
        "cpe": "cpe:/a:redhat:cost_management:4::el9",
        "package": "costmanagement/costmanagement-metrics-rhel9-operator:1770836349"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1769104765"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1769111774"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7261",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssl-main-3.5.6-0.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2485",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1770740405"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2563",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1770646925"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1773670073"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1773672059"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1773670137"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-69421\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-69421"
    ],
    "name": "CVE-2025-69421",
    "mitigation": {
      "value": "Restrict applications from processing untrusted or externally supplied PKCS#12 files, ensuring certificates are sourced only from trusted internal authorities. Additionally, configure critical background services with automatic restart policies (such as systemd's Restart=on-failure) to quickly restore availability if a denial-of-service crash occurs.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2025-07-15T13:44:00Z",
    "bugzilla": {
      "description": "sqlite: Integer Truncation in SQLite",
      "id": "2380149",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380149"
    },
    "cvss3": {
      "cvss3_base_score": "7.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-197",
    "details": [
      "There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.",
      "A memory corruption flaw was found in SQLite. Under specific conditions a query can be generated where the number of aggregate terms could exceed the number of columns available. This issue could lead to memory corruption and subsequent unintended behavior."
    ],
    "statement": "This vulnerability in SQLite is categorized as Important rather than Critical because, although it involves memory corruption, the conditions required to trigger it are relatively constrained. The flaw arises when a query causes the number of aggregate terms to exceed internal limits, leading to potential buffer overflows or memory mismanagement. However, exploitation requires the ability to craft complex SQL queries and interact with the SQLite engine in a specific manner—typically through direct SQL input. There is no known evidence of arbitrary code execution, privilege escalation, or remote exploitability as a direct result of this flaw. Additionally, most SQLite deployments are embedded in applications where input is tightly controlled or sanitized.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:11933",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.0",
        "package": "sqlite-0:3.46.1-5.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2025-07-31T00:00:00Z",
        "advisory": "RHSA-2025:12349",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "sqlite-0:3.7.17-9.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:11803",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nodejs:22-8100020250717142920.6d880403"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:12010",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "sqlite-0:3.26.0-20.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-08-19T00:00:00Z",
        "advisory": "RHSA-2025:14101",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "mingw-sqlite-0:3.26.0.0-2.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:12010",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "sqlite-0:3.26.0-20.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2025-08-05T00:00:00Z",
        "advisory": "RHSA-2025:12901",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "sqlite-0:3.26.0-6.el8_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-01-05T00:00:00Z",
        "advisory": "RHSA-2026:0078",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "spice-client-win-0:8.10-3.el8_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2025-08-05T00:00:00Z",
        "advisory": "RHSA-2025:12905",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "sqlite-0:3.26.0-13.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-01-05T00:00:00Z",
        "advisory": "RHSA-2026:0077",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "spice-client-win-0:8.10-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2025-08-05T00:00:00Z",
        "advisory": "RHSA-2025:12905",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "sqlite-0:3.26.0-13.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-01-05T00:00:00Z",
        "advisory": "RHSA-2026:0077",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "spice-client-win-0:8.10-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2025-08-05T00:00:00Z",
        "advisory": "RHSA-2025:12904",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "sqlite-0:3.26.0-16.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-01-05T00:00:00Z",
        "advisory": "RHSA-2026:0076",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "spice-client-win-0:8.10-3.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2025-08-05T00:00:00Z",
        "advisory": "RHSA-2025:12904",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "sqlite-0:3.26.0-16.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-01-05T00:00:00Z",
        "advisory": "RHSA-2026:0076",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "spice-client-win-0:8.10-3.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2025-08-05T00:00:00Z",
        "advisory": "RHSA-2025:12904",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "sqlite-0:3.26.0-16.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-01-05T00:00:00Z",
        "advisory": "RHSA-2026:0076",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "spice-client-win-0:8.10-3.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12521",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "sqlite-0:3.26.0-18.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-01-05T00:00:00Z",
        "advisory": "RHSA-2026:0001",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "spice-client-win-0:8.10-3.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12521",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "sqlite-0:3.26.0-18.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-01-05T00:00:00Z",
        "advisory": "RHSA-2026:0001",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "spice-client-win-0:8.10-3.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:11802",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nodejs:22-9060020250721113755.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:11992",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "sqlite-0:3.34.1-8.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-11-11T00:00:00Z",
        "advisory": "RHSA-2025:20936",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "sqlite-0:3.34.1-9.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-07-28T00:00:00Z",
        "advisory": "RHSA-2025:11992",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "sqlite-0:3.34.1-8.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-11-11T00:00:00Z",
        "advisory": "RHSA-2025:20936",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "sqlite-0:3.34.1-9.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12522",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "sqlite-0:3.34.1-5.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2025-08-04T00:00:00Z",
        "advisory": "RHSA-2025:12749",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "sqlite-0:3.34.1-6.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-07-29T00:00:00Z",
        "advisory": "RHSA-2025:12036",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "sqlite-0:3.34.1-7.el9_4.1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2025-11-13T00:00:00Z",
        "advisory": "RHSA-2025:19894",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202510291903-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2025-10-23T00:00:00Z",
        "advisory": "RHSA-2025:18240",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202510150118-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2025-10-30T00:00:00Z",
        "advisory": "RHSA-2025:19041",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202510211419-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2025-10-22T00:00:00Z",
        "advisory": "RHSA-2025:18218",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202510112152-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2025-10-29T00:00:00Z",
        "advisory": "RHSA-2025:19046",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202510230424-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2025-10-22T00:00:00Z",
        "advisory": "RHSA-2025:18217",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202510140714-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2025-10-21T00:00:00Z",
        "advisory": "RHSA-2025:15397",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "rhcos-4.20.9.6.202509251656-0"
      },
      {
        "product_name": "Red Hat Web Terminal 1.11 on RHEL 9",
        "release_date": "2025-09-15T00:00:00Z",
        "advisory": "RHSA-2025:15828",
        "cpe": "cpe:/a:redhat:webterminal:1.11::el9",
        "package": "web-terminal/web-terminal-rhel9-operator:1.11-19"
      },
      {
        "product_name": "Red Hat Web Terminal 1.11 on RHEL 9",
        "release_date": "2025-09-15T00:00:00Z",
        "advisory": "RHSA-2025:15828",
        "cpe": "cpe:/a:redhat:webterminal:1.11::el9",
        "package": "web-terminal/web-terminal-tooling-rhel9:1.11-8"
      },
      {
        "product_name": "Red Hat Web Terminal 1.12 on RHEL 9",
        "release_date": "2025-09-15T00:00:00Z",
        "advisory": "RHSA-2025:15827",
        "cpe": "cpe:/a:redhat:webterminal:1.12::el9",
        "package": "web-terminal/web-terminal-tooling-rhel9:1.12-4"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-management-console-rhel8:1.36.0-9"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-operator-bundle:1.36.0-12"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-rhel8-operator:1.36.0-18"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11"
      },
      {
        "product_name": "RHOSS-1.36-RHEL-8",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0934",
        "cpe": "cpe:/a:redhat:openshift_serverless:1.36::el8",
        "package": "openshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7"
      },
      {
        "product_name": "Service Interconnect 1 for RHEL 9",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6481",
        "cpe": "cpe:/a:redhat:service_interconnect:1::el9",
        "package": "service-interconnect/skupper-config-sync-rhel9:1.8.8-1"
      },
      {
        "product_name": "Service Interconnect 1 for RHEL 9",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6481",
        "cpe": "cpe:/a:redhat:service_interconnect:1::el9",
        "package": "service-interconnect/skupper-controller-podman-container-rhel9:1.8.8-1"
      },
      {
        "product_name": "Service Interconnect 1 for RHEL 9",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6481",
        "cpe": "cpe:/a:redhat:service_interconnect:1::el9",
        "package": "service-interconnect/skupper-controller-podman-rhel9:1.8.8-1"
      },
      {
        "product_name": "Service Interconnect 1 for RHEL 9",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6481",
        "cpe": "cpe:/a:redhat:service_interconnect:1::el9",
        "package": "service-interconnect/skupper-flow-collector-rhel9:1.8.8-1"
      },
      {
        "product_name": "Service Interconnect 1 for RHEL 9",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6481",
        "cpe": "cpe:/a:redhat:service_interconnect:1::el9",
        "package": "service-interconnect/skupper-operator-bundle:1.8.8-1"
      },
      {
        "product_name": "Service Interconnect 1 for RHEL 9",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6481",
        "cpe": "cpe:/a:redhat:service_interconnect:1::el9",
        "package": "service-interconnect/skupper-router-rhel9:2.7.6-5"
      },
      {
        "product_name": "Service Interconnect 1 for RHEL 9",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6481",
        "cpe": "cpe:/a:redhat:service_interconnect:1::el9",
        "package": "service-interconnect/skupper-service-controller-rhel9:1.8.8-1"
      },
      {
        "product_name": "Service Interconnect 1 for RHEL 9",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6481",
        "cpe": "cpe:/a:redhat:service_interconnect:1::el9",
        "package": "service-interconnect/skupper-site-controller-rhel9:1.8.8-1"
      },
      {
        "product_name": "cert-manager operator for Red Hat OpenShift 1.16",
        "release_date": "2025-10-16T00:00:00Z",
        "advisory": "RHSA-2025:18219",
        "cpe": "cpe:/a:redhat:cert_manager:1.16::el9",
        "package": "cert-manager/jetstack-cert-manager-rhel9:v1.16.5-1760515757"
      },
      {
        "product_name": "Compliance Operator 1",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21885",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1::el9",
        "package": "compliance/openshift-compliance-content-rhel8:1.8.0"
      },
      {
        "product_name": "Compliance Operator 1",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21885",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1::el9",
        "package": "compliance/openshift-compliance-must-gather-rhel8:1.8.0"
      },
      {
        "product_name": "Compliance Operator 1",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21885",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1::el9",
        "package": "compliance/openshift-compliance-openscap-rhel8:1.8.0"
      },
      {
        "product_name": "Compliance Operator 1",
        "release_date": "2025-11-20T00:00:00Z",
        "advisory": "RHSA-2025:21885",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1::el9",
        "package": "compliance/openshift-compliance-rhel8-operator:1.8.0"
      },
      {
        "product_name": "File Integrity Operator 1",
        "release_date": "2025-11-21T00:00:00Z",
        "advisory": "RHSA-2025:21913",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1::el9",
        "package": "compliance/openshift-file-integrity-rhel8-operator:v1.3"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.7",
        "release_date": "2025-12-16T00:00:00Z",
        "advisory": "RHSA-2025:23248",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
        "package": "advanced-cluster-security/rhacs-collector-rhel8:4.7"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23078",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:3.2.2-1765379088"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23079",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:3.2.2-1765379049"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23080",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:3.2.2-1764871796"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-02-27T00:00:00Z",
        "advisory": "RHSA-2026:3461",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1772160593"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-02-27T00:00:00Z",
        "advisory": "RHSA-2026:3462",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1772160625"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "release_date": "2025-12-01T00:00:00Z",
        "advisory": "RHSA-2025:22529",
        "cpe": "cpe:/a:redhat:ceph_storage:7::el9",
        "package": "rhceph/rhceph-7-rhel9:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "release_date": "2025-12-02T00:00:00Z",
        "advisory": "RHSA-2025:22548",
        "cpe": "cpe:/a:redhat:ceph_storage:8::el9",
        "package": "rhceph/rhceph-8-rhel9:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1652",
        "cpe": "cpe:/a:redhat:ceph_storage:8::el9",
        "package": "rhceph/rhceph-8-rhel9:1769512383"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2025-08-06T00:00:00Z",
        "advisory": "RHSA-2025:13267",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:2.0.1-1754478727"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2025-11-24T00:00:00Z",
        "advisory": "RHSA-2025:21994",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:2.4.0-1763596485"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2025-11-24T00:00:00Z",
        "advisory": "RHSA-2025:21994",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:2.4.0-1763656152"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2025-08-07T00:00:00Z",
        "advisory": "RHSA-2025:13335",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1.5.5-1754504343"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2025-12-08T00:00:00Z",
        "advisory": "RHSA-2025:22868",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1.5.9-1765201856"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "rust-toolset:rhel8/rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-6965\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-6965\nhttps://www.oracle.com/security-alerts/cpujan2026.html#AppendixMSQL\nhttps://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8"
    ],
    "name": "CVE-2025-6965",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-03-12T00:00:00Z",
    "bugzilla": {
      "description": "sqlite: SQLite: Information Disclosure via Crafted ZIP File",
      "id": "2447086",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447086"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-908",
    "details": [
      "An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.",
      "A flaw was found in SQLite. This information disclosure vulnerability exists within the zipfile extension, specifically in the zipfileInflate function. A remote attacker could exploit this by providing a specially crafted ZIP file. Successful exploitation could lead to the disclosure of sensitive heap memory information."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-11T00:00:00Z",
        "advisory": "RHSA-2026:7656",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "sqlite-main-3.52.0-1.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:22/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:24/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "rust-toolset:rhel8/rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:22/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:24/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-70873\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-70873\nhttps://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054\nhttps://sqlite.org/forum/forumpost/761eac3c82\nhttps://sqlite.org/src/info/3d459f1fb1bd1b5e"
    ],
    "name": "CVE-2025-70873",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-04T00:00:00Z",
    "bugzilla": {
      "description": "kernel: Kernel: Memory corruption via double free in ALSA AC97 controller",
      "id": "2436772",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436772"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-1341",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nALSA: ac97: fix a double free in snd_ac97_controller_register()\nIf ac97_add_adapter() fails, put_device() is the correct way to drop\nthe device reference. kfree() is not required.\nAdd kfree() if idr_alloc() fails and in ac97_adapter_release() to do\nthe cleanup.\nFound by code review.",
      "A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) AC97 controller. A double free vulnerability exists in the `snd_ac97_controller_register()` function when `ac97_add_adapter()` fails. A local attacker could exploit this flaw, leading to memory corruption and potentially a denial of service or privilege escalation."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-71192\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-71192\nhttps://lore.kernel.org/linux-cve-announce/2026020438-CVE-2025-71192-3370@gregkh/T"
    ],
    "name": "CVE-2025-71192",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-04T00:00:00Z",
    "bugzilla": {
      "description": "kernel: iio: adc: at91-sama5d2_adc: Fix potential use-after-free in sama5d2_adc driver",
      "id": "2436758",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436758"
    },
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\niio: adc: at91-sama5d2_adc: Fix potential use-after-free in sama5d2_adc driver\nat91_adc_interrupt can call at91_adc_touch_data_handler function\nto start the work by schedule_work(&st->touch_st.workq).\nIf we remove the module which will call at91_adc_remove to\nmake cleanup, it will free indio_dev through iio_device_unregister but\nquite a bit later. While the work mentioned above will be used. The\nsequence of operations that may lead to a UAF bug is as follows:\nCPU0                                      CPU1\n| at91_adc_workq_handler\nat91_adc_remove                      |\niio_device_unregister(indio_dev)     |\n//free indio_dev a bit later         |\n| iio_push_to_buffers(indio_dev)\n| //use indio_dev\nFix it by ensuring that the work is canceled before proceeding with\nthe cleanup in at91_adc_remove."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-71199\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-71199\nhttps://lore.kernel.org/linux-cve-announce/2026020412-CVE-2025-71199-9a60@gregkh/T"
    ],
    "name": "CVE-2025-71199",
    "csaw": false
  },
  {
    "public_date": "2026-02-18T00:00:00Z",
    "bugzilla": {
      "description": "kernel: nilfs2: Fix potential block overflow that cause system hang",
      "id": "2440671",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2440671"
    },
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nnilfs2: Fix potential block overflow that cause system hang\nWhen a user executes the FITRIM command, an underflow can occur when\ncalculating nblocks if end_block is too small. Since nblocks is of\ntype sector_t, which is u64, a negative nblocks value will become a\nvery large positive integer. This ultimately leads to the block layer\nfunction __blkdev_issue_discard() taking an excessively long time to\nprocess the bio chain, and the ns_segctor_sem lock remains held for a\nlong period. This prevents other tasks from acquiring the ns_segctor_sem\nlock, resulting in the hang reported by syzbot in [1].\nIf the ending block is too small, typically if it is smaller than 4KiB\nrange, depending on the usage of the segment 0, it may be possible to\nattempt a discard request beyond the device size causing the hang.\nExiting successfully and assign the discarded size (0 in this case)\nto range->len.\nAlthough the start and len values in the user input range are too small,\na conservative strategy is adopted here to safely ignore them, which is\nequivalent to a no-op; it will not perform any trimming and will not\nthrow an error.\n[1]\ntask:segctord state:D stack:28968 pid:6093 tgid:6093  ppid:2 task_flags:0x200040 flags:0x00080000\nCall Trace:\nrwbase_write_lock+0x3dd/0x750 kernel/locking/rwbase_rt.c:272\nnilfs_transaction_lock+0x253/0x4c0 fs/nilfs2/segment.c:357\nnilfs_segctor_thread_construct fs/nilfs2/segment.c:2569 [inline]\nnilfs_segctor_thread+0x6ec/0xe00 fs/nilfs2/segment.c:2684\n[ryusuke: corrected part of the commit message about the consequences]"
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-71237\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-71237\nhttps://lore.kernel.org/linux-cve-announce/2026021806-CVE-2025-71237-545a@gregkh/T"
    ],
    "name": "CVE-2025-71237",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-30T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902bde9b7cdea145. It has been classified as problematic. This affects the function pdf_ferror of the file devices/vector/gdevpdf.c of the component New Output File Open Error Handler. The manipulation leads to null pointer dereference. It is possible to initiate the attack remotely. The identifier of the patch is 619a106ba4c4abed95110f84d5efcd7aee38c7cb. It is recommended to apply a patch to fix this issue."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-7462\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-7462"
    ],
    "name": "CVE-2025-7462",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-10-07T18:10:05Z",
    "bugzilla": {
      "description": "cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked",
      "id": "2402342",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-130",
    "details": [
      "The 'zipfile' module would not check the validity of the ZIP64 End of\nCentral Directory (EOCD) Locator record offset value would not be used to\nlocate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be\nassumed to be the previous record in the ZIP archive. This could be abused\nto create ZIP archives that are handled differently by the 'zipfile' module\ncompared to other ZIP implementations.\nRemediation maintains this behavior, but checks that the offset specified\nin the ZIP64 EOCD Locator record matches the expected value.",
      "A zip file handling flaw has been discovered in the python standard library `zipfile` module. The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-12-22T00:00:00Z",
        "advisory": "RHSA-2025:23940",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "python3.12-0:3.12.12-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0353",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "python3.12-0:3.12.9-2.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python39:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23530",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python39-devel:3.9-8100020251126112422.d47b87a4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-06T00:00:00Z",
        "advisory": "RHSA-2026:0123",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.12-0:3.12.12-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23323",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.12-0:3.12.12-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23342",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.25-2.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-12-18T00:00:00Z",
        "advisory": "RHSA-2025:23342",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.25-2.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0354",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.12-0:3.12.1-4.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0355",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "python3.12-0:3.12.9-1.el9_6.3"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "release_date": "2026-02-03T00:00:00Z",
        "advisory": "RHSA-2026:1858",
        "cpe": "cpe:/a:redhat:ceph_storage:7::el9",
        "package": "rhceph/rhceph-7-rhel9:1769508455"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1652",
        "cpe": "cpe:/a:redhat:ceph_storage:8::el9",
        "package": "rhceph/rhceph-8-rhel9:1769512383"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0414",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1767888970"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0414",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1767904573"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7443",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-13-main-3.13.13-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-11T00:00:00Z",
        "advisory": "RHSA-2026:7661",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-14-main-3.14.4-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8822",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-11-main-3.11.15-4.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8824",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-12-main-3.12.13-3.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0685",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1768221107"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0685",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1768221100"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0685",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1768296285"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0685",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1768377012"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3.11",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-aws-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-azure-amd-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-azure-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-gcp-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI)",
        "fix_state": "Fix deferred",
        "package_name": "rhelai1/bootc-nvidia-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-8291\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-8291\nhttps://github.com/python/cpython/commit/162997bb70e067668c039700141770687bc8f267\nhttps://github.com/python/cpython/commit/333d4a6f4967d3ace91492a39ededbcf3faa76a6\nhttps://github.com/python/cpython/issues/139700\nhttps://github.com/python/cpython/pull/139702\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/QECOPWMTH4VPPJAXAH2BGTA4XADOP62G/"
    ],
    "name": "CVE-2025-8291",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2025-09-30T23:59:00Z",
    "bugzilla": {
      "description": "openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap",
      "id": "2396054",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2396054"
    },
    "cvss3": {
      "cvss3_base_score": "5.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "Issue summary: An application trying to decrypt CMS messages encrypted using\npassword based encryption can trigger an out-of-bounds read and write.\nImpact summary: This out-of-bounds read may trigger a crash which leads to\nDenial of Service for an application. The out-of-bounds write can cause\na memory corruption which can have various consequences including\na Denial of Service or Execution of attacker-supplied code.\nAlthough the consequences of a successful exploit of this vulnerability\ncould be severe, the probability that the attacker would be able to\nperform it is low. Besides, password based (PWRI) encryption support in CMS\nmessages is very rarely used. For that reason the issue was assessed as\nModerate severity according to our Security Policy.\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary.",
      "A flaw was found in the OpenSSL CMS implementation (RFC 3211 KEK Unwrap). This vulnerability allows memory corruption, an application level denial of service, or potential execution of attacker-supplied code via crafted CMS messages using password-based encryption (PWRI)."
    ],
    "statement": "The vulnerability was rated as Moderate because, while the potential impact includes an application level denial of service and possible arbitrary code execution, successful exploitation is considered unlikely due to the high attack complexity and the fact that password-based CMS encryption (PWRI) is rarely used in real-world deployments.",
    "affected_release": [
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2994",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2025-11-13T00:00:00Z",
        "advisory": "RHSA-2025:21248",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssl-1:3.5.1-4.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18320",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "edk2-0:20250822-4.el10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2025-12-08T00:00:00Z",
        "advisory": "RHSA-2025:22794",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "openssl-1:3.2.2-16.el10_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1720",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "openssl-1:1.0.2k-26.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36721",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "edk2-0:20220126gitbb1bba3d77-13.el8_10.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0337",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "openssl-1:1.1.1k-14.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-01-20T00:00:00Z",
        "advisory": "RHSA-2026:0887",
        "cpe": "cpe:/o:redhat:rhel_aus:8.2",
        "package": "openssl-1:1.1.1c-21.el8_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1475",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "openssl-1:1.1.1g-18.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1475",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "openssl-1:1.1.1g-18.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0714",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "openssl-1:1.1.1k-14.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0714",
        "cpe": "cpe:/o:redhat:rhel_tus:8.6",
        "package": "openssl-1:1.1.1k-14.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0714",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.6",
        "package": "openssl-1:1.1.1k-14.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35846",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "edk2-0:20220126gitbb1bba3d77-4.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-01-14T00:00:00Z",
        "advisory": "RHSA-2026:0602",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "openssl-1:1.1.1k-14.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35846",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "edk2-0:20220126gitbb1bba3d77-4.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-01-14T00:00:00Z",
        "advisory": "RHSA-2026:0602",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "openssl-1:1.1.1k-14.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-11-13T00:00:00Z",
        "advisory": "RHSA-2025:21255",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-4.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2776",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "edk2-0:20241117-4.el9_7.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2025-11-13T00:00:00Z",
        "advisory": "RHSA-2025:21255",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-4.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-01-27T00:00:00Z",
        "advisory": "RHSA-2026:1349",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "openssl-1:3.0.1-46.el9_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-01-27T00:00:00Z",
        "advisory": "RHSA-2026:1349",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "openssl-fips-provider-0:3.0.7-1.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-01-19T00:00:00Z",
        "advisory": "RHSA-2026:0794",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "openssl-1:3.0.7-18.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-01-19T00:00:00Z",
        "advisory": "RHSA-2026:0794",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "openssl-fips-provider-0:3.0.7-1.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2025-11-17T00:00:00Z",
        "advisory": "RHSA-2025:21562",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "openssl-1:3.0.7-29.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3164",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "edk2-0:20231122-6.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2025-11-12T00:00:00Z",
        "advisory": "RHSA-2025:21174",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "openssl-1:3.2.2-7.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2771",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "edk2-0:20241117-2.el9_6.2"
      },
      {
        "product_name": "Red Hat JBoss Core Services 2.4.62.SP3",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:2995",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "openssl"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:3861",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202603041314-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-03-05T00:00:00Z",
        "advisory": "RHSA-2026:3415",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202602240113-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:2974",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202602171627-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0702",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202601120213-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-01-15T00:00:00Z",
        "advisory": "RHSA-2026:0332",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202601071817-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-01-22T00:00:00Z",
        "advisory": "RHSA-2026:0674",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202601130152-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-01-14T00:00:00Z",
        "advisory": "RHSA-2026:0420",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "rhcos-4.20.9.6.202601052146-0"
      },
      {
        "product_name": "Red Hat Satellite 6.16 for RHEL 8",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50223",
        "cpe": "cpe:/a:redhat:satellite:6.16::el8",
        "package": "openvox-agent-0:8.24.1-3.el8sat"
      },
      {
        "product_name": "Red Hat Satellite 6.16 for RHEL 8",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50223",
        "cpe": "cpe:/a:redhat:satellite_capsule:6.16::el8",
        "package": "openvox-agent-0:8.24.1-3.el8sat"
      },
      {
        "product_name": "Red Hat Satellite 6.16 for RHEL 9",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50223",
        "cpe": "cpe:/a:redhat:satellite:6.16::el9",
        "package": "openvox-agent-0:8.24.1-3.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.16 for RHEL 9",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50223",
        "cpe": "cpe:/a:redhat:satellite_capsule:6.16::el9",
        "package": "openvox-agent-0:8.24.1-3.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50222",
        "cpe": "cpe:/a:redhat:satellite:6.17::el9",
        "package": "openvox-agent-0:8.24.1-3.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50222",
        "cpe": "cpe:/a:redhat:satellite_capsule:6.17::el9",
        "package": "openvox-agent-0:8.24.1-3.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.18 for RHEL 9",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50263",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "openvox-agent-0:8.24.1-3.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.18 for RHEL 9",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50263",
        "cpe": "cpe:/a:redhat:satellite_capsule:6.18::el9",
        "package": "openvox-agent-0:8.24.1-3.el9sat"
      },
      {
        "product_name": "Cost Management Metrics Operator 4",
        "release_date": "2025-12-01T00:00:00Z",
        "advisory": "RHSA-2025:22428",
        "cpe": "cpe:/a:redhat:cost_management:4::el9",
        "package": "costmanagement/costmanagement-metrics-rhel9-operator:4.3.0-1763050722"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23078",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:3.2.2-1765379088"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23079",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:3.2.2-1765379049"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2025-12-10T00:00:00Z",
        "advisory": "RHSA-2025:23080",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:3.2.2-1764871796"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2025-12-15T00:00:00Z",
        "advisory": "RHSA-2025:23202",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:3.2.5-1765361184"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2025-12-15T00:00:00Z",
        "advisory": "RHSA-2025:23204",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:3.2.5-1765552580"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2025-12-15T00:00:00Z",
        "advisory": "RHSA-2025:23205",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:3.2.5-1765361180"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2025-12-15T00:00:00Z",
        "advisory": "RHSA-2025:23209",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-tpu-rhel9:3.2.5-1765552619"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2025-12-17T00:00:00Z",
        "advisory": "RHSA-2025:23449",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:3.2.5-1765552603"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-02-27T00:00:00Z",
        "advisory": "RHSA-2026:3461",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1772160593"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-02-27T00:00:00Z",
        "advisory": "RHSA-2026:3462",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1772160625"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "release_date": "2025-12-01T00:00:00Z",
        "advisory": "RHSA-2025:22529",
        "cpe": "cpe:/a:redhat:ceph_storage:7::el9",
        "package": "rhceph/rhceph-7-rhel9:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "release_date": "2025-12-02T00:00:00Z",
        "advisory": "RHSA-2025:22548",
        "cpe": "cpe:/a:redhat:ceph_storage:8::el9",
        "package": "rhceph/rhceph-8-rhel9:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1652",
        "cpe": "cpe:/a:redhat:ceph_storage:8::el9",
        "package": "rhceph/rhceph-8-rhel9:1769512383"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2025-11-24T00:00:00Z",
        "advisory": "RHSA-2025:21994",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:2.4.0-1763596485"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2025-11-24T00:00:00Z",
        "advisory": "RHSA-2025:21994",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:2.4.0-1763656152"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7261",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssl-main-3.5.6-0.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2025-12-08T00:00:00Z",
        "advisory": "RHSA-2025:22868",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1.5.9-1765201856"
      }
    ],
    "package_state": [
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicloud-operators-foundation",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/hypershift-addon-rhel9-operator",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine-placement-container",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/registration-operator-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/registration-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine-work-container",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "acm-cluster-manager-addon-manager-controller-container",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "acm-config-policy-controller-container",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "acm-governance-policy-framework-container",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "acm-governance-policy-propagator-container",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "acm-multicluster-engine-operator-container",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-governance-policy-addon-controller-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/clusterlifecycle-state-metrics-rhel8",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/klusterlet-addon-controller-rhel8",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "python3.12-pyOpenSSL",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "python-pyOpenSSL",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite-capsule:el8/python-pyOpenSSL",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite:el8/python-pyOpenSSL",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite Client",
        "fix_state": "Affected",
        "package_name": "puppet-agent",
        "cpe": "cpe:/a:redhat:rhel_satellite_client:6::el7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-9230\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-9230"
    ],
    "name": "CVE-2025-9230",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-08-25T02:02:07Z",
    "bugzilla": {
      "description": "jq: assertion failure in run_jq_tests() of the file jq_test.c",
      "id": "2390651",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2390651"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-617",
    "details": [
      "A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well.",
      "A vulnerability has been identified in the jq JSON processor where malformed JSON input containing invalid Unicode escape sequences can trigger an assertion failure in the test suite’s parsing consistency checks. This flaw arises from inconsistencies between expected and reparsed JSON values during serialization and deserialization, potentially allowing an attacker to exploit the issue by supplying specially crafted JSON data to cause abnormal termination or denial of service during test execution, highlighting weaknesses in jq’s parsing reliability."
    ],
    "statement": "This vulnerability is limited to jq’s internal test framework and does not affect jq’s core functionality in production use. Exploitation requires supplying malformed JSON with invalid Unicode escape sequences during test execution, which can trigger an assertion failure and abnormal termination of the test suite. The issue is rated Low severity as it only causes test crashes in debug or development environments, without exposing sensitive data, compromising system integrity, or affecting jq’s normal JSON processing in production.",
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Out of support scope",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Trusted Application Pipeline",
        "fix_state": "Fix deferred",
        "package_name": "rhtap-cli/rhtap-cli-rhel9",
        "cpe": "cpe:/a:redhat:trusted_application_pipeline:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-9403\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-9403\nhttps://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing\nhttps://github.com/jqlang/jq/issues/3393\nhttps://vuldb.com/?ctiid.321239\nhttps://vuldb.com/?id.321239\nhttps://vuldb.com/?submit.633170"
    ],
    "name": "CVE-2025-9403",
    "mitigation": {
      "value": "No action is required for production users, as the vulnerability only affects jq’s internal test framework and does not impact its core JSON processing functionality. Standard deployments of jq remain unaffected. Developers and testers are advised to avoid running the test suite with untrusted or malformed JSON input until a fix is applied.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2025-12-12T00:00:00Z",
    "bugzilla": {
      "description": "NetworkManager: NetworkManager File Access",
      "id": "2391503",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2391503"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-281",
    "details": [
      "A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.",
      "A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18142",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "NetworkManager-1:1.56.0-1.el10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18597",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "NetworkManager-1:1.54.3-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18597",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "NetworkManager-1:1.54.3-2.el9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2025-9615\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-9615\nhttps://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/issues/1809\nhttps://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2324\nhttps://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2327"
    ],
    "name": "CVE-2025-9615",
    "mitigation": {
      "value": "SELinux is shipped out of the box in targeted enforcing mode, which prevents processes from having unwanted permissions and mitigates this attack.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-27T08:10:17Z",
    "bugzilla": {
      "description": "dovecot: Dovecot: Information disclosure and authentication bypass via path traversal",
      "id": "2452173",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452173"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-22",
    "details": [
      "When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is directory partial. This allows inadvertently reading /etc/passwd (or some other path which ends with passwd). If this file contains passwords, it can be used to authenticate wrongly, or if this is userdb, it can unexpectly make system users appear valid users.  Upgrade to fixed version, or use different authentication scheme that does not rely on paths. Alternatively you can also ensure that the per-domain passwd files are in some other location, such as /etc/dovecot/auth/%d. No publicly available exploits are known.",
      "A flaw was found in dovecot. When configured to use per-domain password files, a path traversal vulnerability can be exploited by a remote attacker. This occurs if the password files are located one directory level above /etc or if a slash character is permitted in the domain component, allowing partial control over the directory path. Successful exploitation enables the attacker to read sensitive files, such as /etc/passwd, which could lead to unauthorized authentication or the unexpected validation of system users."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-0394\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-0394\nhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json"
    ],
    "name": "CVE-2026-0394",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-20T21:52:33Z",
    "bugzilla": {
      "description": "cpython: Header injection in http.cookies.Morsel in Python",
      "id": "2431374",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-93",
    "details": [
      "When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.",
      "An injection flaw has been discovered in Python. When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19064",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "python3.12-0:3.12.13-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10950",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.12-0:3.12.13-2.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19177",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.12-0:3.12.13-2.el9_8"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python3.14",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3.11",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python39-devel:3.9/python39",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.14",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.9",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-0672\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-0672\nhttps://github.com/python/cpython/issues/143919\nhttps://github.com/python/cpython/pull/143920"
    ],
    "name": "CVE-2026-0672",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-23T17:42:01Z",
    "bugzilla": {
      "description": "python: cpython: Python configparser: Configuration injection via crafted multi-line input",
      "id": "2491892",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491892"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
      "status": "draft"
    },
    "cwe": "CWE-93",
    "details": [
      "When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.",
      "A flaw was found in the Python `configparser` module. When writing configuration files, an attacker who controls the input value can inject unexpected keys and values. This occurs if the input contains multi-line text with carriage return characters, leading to potential configuration manipulation."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-0864\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-0864\nhttps://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f\nhttps://github.com/python/cpython/issues/143927\nhttps://github.com/python/cpython/pull/151559\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"
    ],
    "name": "CVE-2026-0864",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-20T21:26:15Z",
    "bugzilla": {
      "description": "cpython: wsgiref.headers.Headers allows header newline injection in Python",
      "id": "2431367",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431367"
    },
    "cvss3": {
      "cvss3_base_score": "4.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-74",
    "details": [
      "User-controlled header names and values containing newlines can allow injecting HTTP headers.",
      "Missing newline filtering has been discovered in Python. User-controlled header names and values containing newlines can allow injecting HTTP headers."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4713",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "python3.12-0:3.12.12-3.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19019",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "python3.14-0:3.14.4-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:2128",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-73.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4463",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.12-0:3.12.12-3.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4473",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.11-0:3.11.13-5.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:2128",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "python3-0:3.6.8-73.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18693",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.25-5.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18957",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.11-0:3.11.13-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18958",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.12-0:3.12.12-6.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19176",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.14-0:3.14.4-2.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4168",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.25-3.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18693",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.25-5.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4168",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "python3.9-0:3.9.25-3.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6253",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python3.11-0:3.11.7-1.el9_4.11"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5606",
        "cpe": "cpe:/a:redhat:ceph_storage:8::el9",
        "package": "rhceph/rhceph-8-rhel9:1774002867"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7443",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-13-main-3.13.13-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-11T00:00:00Z",
        "advisory": "RHSA-2026:7661",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-14-main-3.14.4-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8822",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-11-main-3.11.15-4.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8824",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-12-main-3.12.13-3.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1779798159"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1779798164"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1773670073"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1773672059"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1773668803"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1773670137"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python39-devel:3.9/python39",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-0865\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-0865\nhttps://github.com/python/cpython/issues/143916\nhttps://github.com/python/cpython/pull/143917\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/BJ6QPHNSHJTS3A7CFV6IBMCAP2DWRVNT/"
    ],
    "name": "CVE-2026-0865",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-10T18:44:42Z",
    "bugzilla": {
      "description": "libssh: Improper sanitation of paths received from SCP servers",
      "id": "2436979",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-22",
    "details": [
      "A malicious SCP server can send unexpected paths that could make the\nclient application override local files outside of working directory.\nThis could be misused to create malicious executable or configuration\nfiles and make the user execute them under specific consequences.\nThis is the same issue as in OpenSSH, tracked as CVE-2019-6111.",
      "A malicious SCP server can send unexpected paths that could make the\nclient application override local files outside of working directory.\nThis could be misused to create malicious executable or configuration\nfiles and make the user execute them under specific consequences.\nThis is the same issue as in OpenSSH, tracked as CVE-2019-6111."
    ],
    "acknowledgement": "Red Hat would like to thank CTyun (Red-Shield Security Lab) and Jakub Jelen (libssh) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18160",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libssh-0:0.12.0-2.el10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18683",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libssh-0:0.10.4-18.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18683",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libssh-0:0.10.4-18.el9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-0964\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-0964\nhttps://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
    ],
    "name": "CVE-2026-0964",
    "mitigation": {
      "value": "Do not use SCP! SCP is deprecated for several years and will\nbe removed in future releases!\nIf you have to, the application MUST validate the path returned\nfrom `ssh_scp_request_get_filename()` is the path the application\nrequested. The libssh does not do any writing in this case.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-02-10T18:47:22Z",
    "bugzilla": {
      "description": "libssh: libssh: Denial of Service via improper configuration file handling",
      "id": "2436980",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-73",
    "details": [
      "A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.",
      "A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations."
    ],
    "acknowledgement": "Red Hat would like to thank Jakub Jelen (libssh) and Kang Yang for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18160",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libssh-0:0.12.0-2.el10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18683",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libssh-0:0.10.4-18.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18683",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libssh-0:0.10.4-18.el9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-0965\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-0965"
    ],
    "name": "CVE-2026-0965",
    "mitigation": {
      "value": "Ensure the client and server are using only regular files as configuration.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-10T18:47:15Z",
    "bugzilla": {
      "description": "libssh: libssh: Denial of Service via zero-length input in ssh_get_hexa()",
      "id": "2433121",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-124",
    "details": [
      "A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.",
      "A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process."
    ],
    "statement": "Attack Complexity is high as it requires the logging verbosity to be set to `SSH_LOG_PACKET (3)` or higher, which is not the default configuration in Red Hat Enterprise Linux.",
    "acknowledgement": "Red Hat would like to thank Jakub Jelen (libssh), Jun Xu, Kang Yang, and Yunhang Zhang for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18160",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libssh-0:0.12.0-2.el10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18683",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libssh-0:0.10.4-18.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18683",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libssh-0:0.10.4-18.el9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7067",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libssh-main-0.12.0-1.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-0966\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-0966\nhttps://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
    ],
    "name": "CVE-2026-0966",
    "mitigation": {
      "value": "To mitigate this issue, consider disabling GSSAPI authentication if it is not required, or reduce the `LogLevel` in the `sshd_config` file to a value lower than `SSH_LOG_PACKET` (e.g., `INFO`).\nTo disable GSSAPI authentication, add or modify the following line in `/etc/ssh/sshd_config`:\n`GSSAPIAuthentication no`\nTo reduce logging verbosity, add or modify the following line in `/etc/ssh/sshd_config`:\n`LogLevel INFO`\nAfter making changes to `sshd_config`, the `sshd` service must be restarted for the changes to take effect. This may temporarily interrupt active SSH sessions.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-02-10T18:47:09Z",
    "bugzilla": {
      "description": "libssh: libssh: Denial of Service via inefficient regular expression processing",
      "id": "2436981",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
    },
    "cvss3": {
      "cvss3_base_score": "2.2",
      "cvss3_scoring_vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-1333",
    "details": [
      "A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.",
      "A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client."
    ],
    "statement": "The vulnerability in libssh has been rated as Low by Red Hat Product Security.\nThis issue arises from inefficient pattern matching logic that may lead to excessive processing time when handling specially crafted patterns. However, these patterns originate from configuration data, meaning an attacker would need the ability to modify or influence configuration files to exploit the issue.\nAs a result, exploitation requires local access or equivalent local privileges, and cannot be performed remotely without prior compromise. Additionally, triggering the issue depends on specific conditions during pattern evaluation, increasing the attack complexity.\nThe impact of this flaw is limited to potential performance degradation or temporary delays due to increased CPU usage. It does not allow unauthorized access to data, modification of system state, or execution of arbitrary code.",
    "acknowledgement": "Red Hat would like to thank Jakub Jelen (libssh) and Kang Yang for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18160",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libssh-0:0.12.0-2.el10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18683",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libssh-0:0.10.4-18.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18683",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libssh-0:0.10.4-18.el9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-0967\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-0967\nhttps://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
    ],
    "name": "CVE-2026-0967",
    "mitigation": {
      "value": "Avoid using complex patterns in configuration files and known_hosts.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-02-10T18:46:58Z",
    "bugzilla": {
      "description": "libssh: libssh: Denial of Service due to malformed SFTP message",
      "id": "2436982",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
    },
    "cvss3": {
      "cvss3_base_score": "3.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.",
      "A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes."
    ],
    "statement": "The vulnerability in libssh has been rated as Low by Red Hat Product Security.\nThis issue affects the libssh client when processing responses from an SFTP server. Successful exploitation requires a user to initiate a connection to a malicious or compromised SFTP server and perform specific operations, such as listing directory contents. As a result, exploitation is not possible without user interaction.\nAdditionally, the vulnerability depends on specially crafted protocol responses from a malicious server, increasing the attack complexity and reducing the likelihood of successful exploitation in typical deployments. \nThe impact of this flaw is limited to a client-side denial-of-service condition, such as an application crash. There is no evidence that this issue can be leveraged to execute arbitrary code, access sensitive information, or modify data.\nDue to the requirement for user interaction, higher attack complexity, and limited impact on availability only, Red Hat considers this vulnerability to have a lower risk.",
    "acknowledgement": "Red Hat would like to thank Jakub Jelen (libssh) and nevv (CTyun Red-Shield Security Lab) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18160",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libssh-0:0.12.0-2.el10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18683",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libssh-0:0.10.4-18.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18683",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libssh-0:0.10.4-18.el9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "libssh2",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-0968\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-0968\nhttps://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
    ],
    "name": "CVE-2026-0968",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-05-28T22:27:36Z",
    "bugzilla": {
      "description": "glib-networking: Infinite loop in glib-networking GnuTLS backend allows remote denial of service via circular certificate chain",
      "id": "2465152",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2465152"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-835",
    "details": [
      "A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted certificate chain to an application that uses glib-networking with the GnuTLS backend enabled and performs certificate verification. This crafted chain, which contains circular issuer relationships, can cause an infinite loop during certificate verification. The unbounded traversal consumes excessive CPU resources, leading to a denial of service for the affected process or worker.",
      "A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted certificate chain to an application that uses glib-networking with the GnuTLS backend enabled and performs certificate verification. This crafted chain, which contains circular issuer relationships, can cause an infinite loop during certificate verification. The unbounded traversal consumes excessive CPU resources, leading to a denial of service for the affected process or worker."
    ],
    "statement": "There's a vulnerability in the `glib-networking` package, where a server with a maliciously crafted certificate chain can lead the application using the `glib-networking` libraries with GnuTLS backend to an excessive CPU consumption and cause a Denial-of-Service as consequence of it. The vulnerability happens when the application is performing a certificate validation and the crafted certificate chain contains a circular issuer relationship. For latest `glib-networking` versions such as shipped with Red Hat Enterprise Linux 10, this can lead the client application to freeze when connecting to a malicious server holding the crafted certificate chain resulting in an availability impact to the specific execution on the process (A:L). For versions of `glib-networking` as shipped with Red Hat Enterprise Linux 9 and older, it's possible that an attacker may be able to cause a Denial-of-Service in a server application which does the same kind of validation depending on certain scenarios.\nRed Hat Product Security team has rated this vulnerability as having a Low impact since, in general, the result of a exploitation needs the user to be tricked to connect to a malicious server and would have a low availability impact as consequence.",
    "acknowledgement": "Red Hat would like to thank AISLE Research for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "glib-networking",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "glib-networking",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "glib-networking",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "glib-networking",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "glib-networking",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-10028\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-10028\nhttps://gitlab.gnome.org/GNOME/glib-networking/-/work_items/231"
    ],
    "name": "CVE-2026-10028",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-01T15:25:35Z",
    "bugzilla": {
      "description": "poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication",
      "id": "2460428",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460428"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.",
      "A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF."
    ],
    "statement": "This is an Important heap-based memory corruption flaw in Poppler's Splash backend. Processing a specially crafted PDF document can lead to an integer overflow, resulting in an undersized heap allocation and a subsequent out-of-bounds write. This could allow an attacker to achieve arbitrary code execution, disclose sensitive information, or cause a denial of service within the context of the application rendering the PDF. To successfully exploit this vulnerability the attacker needs to be able to supply the maliciously crafted PDF file to the application consuming poppler or trick the user to process the PDF file using the Poppler's backend.",
    "acknowledgement": "This issue was discovered by AISLE Research and AISLE in partnership with Red Hat.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24985",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "poppler-0:24.02.0-7.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27720",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "poppler-0:24.02.0-7.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29952",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "compat-poppler022-0:0.22.5-7.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30044",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "poppler-0:0.26.5-44.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24984",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "poppler-0:20.11.0-14.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27727",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "poppler-0:20.11.0-2.el8_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27727",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "poppler-0:20.11.0-2.el8_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27725",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "poppler-0:20.11.0-5.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27725",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "poppler-0:20.11.0-5.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27724",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "poppler-0:20.11.0-7.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27724",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "poppler-0:20.11.0-7.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25058",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "poppler-0:21.01.0-24.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27723",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "poppler-0:21.01.0-15.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27722",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "poppler-0:21.01.0-20.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27721",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "poppler-0:21.01.0-22.el9_6.1"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30078",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1782352950"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30087",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1782352919"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30088",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782353093"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30089",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1782352847"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30134",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "poppler-main-26.06.0-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "poppler",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-10118\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-10118\nhttps://gitlab.freedesktop.org/poppler/poppler/-/work_items/1715"
    ],
    "name": "CVE-2026-10118",
    "mitigation": {
      "value": "To mitigate this issue, users should avoid opening untrusted or suspicious PDF documents with applications that utilize the Poppler library for rendering. Limiting exposure to untrusted content can reduce the risk of exploitation.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-02T21:15:10Z",
    "bugzilla": {
      "description": "libwebsockets: libwebsockets: Denial of Service via SSH Protocol Handler resource consumption",
      "id": "2484180",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484180"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-130",
    "details": [
      "A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Handler. Executing a manipulation of the argument msg_len can lead to resource consumption. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498. A patch should be applied to remediate this issue.",
      "A flaw was found in libwebsockets, specifically within its SSH Protocol Handler component. A remote attacker can exploit this vulnerability by manipulating the 'msg_len' argument in the 'lws_ssh_parse_plaintext' function. This manipulation can lead to excessive resource consumption, resulting in a Denial of Service (DoS) condition for the affected system."
    ],
    "package_state": [
      {
        "product_name": "A-MQ Interconnect 1",
        "fix_state": "Fix deferred",
        "package_name": "libwebsockets",
        "cpe": "cpe:/a:redhat:amq_interconnect:1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "libwebsockets",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "libwebsockets",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat Service Interconnect 1",
        "fix_state": "Fix deferred",
        "package_name": "libwebsockets",
        "cpe": "cpe:/a:redhat:service_interconnect:1"
      },
      {
        "product_name": "Red Hat Service Interconnect 2",
        "fix_state": "Fix deferred",
        "package_name": "libwebsockets",
        "cpe": "cpe:/a:redhat:service_interconnect:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-10650\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-10650\nhttps://github.com/biniamf/pocs/blob/main/libwebsockets_sshd-parse-ic-unbounded-alloc/poc_sshd_unbounded_alloc.py\nhttps://github.com/biniamf/pocs/tree/main/libwebsockets_sshd-parse-ic-unbounded-alloc\nhttps://github.com/warmcat/libwebsockets/\nhttps://github.com/warmcat/libwebsockets/commit/3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498\nhttps://vuldb.com/cve/CVE-2026-10650\nhttps://vuldb.com/submit/830261\nhttps://vuldb.com/vuln/367955\nhttps://vuldb.com/vuln/367955/cti"
    ],
    "name": "CVE-2026-10650",
    "mitigation": {
      "value": "To mitigate this issue, restrict network access to systems running the libwebsockets SSH Protocol Handler to trusted clients only. If the SSH Protocol Handler functionality is not required, consider disabling or removing components that utilize it to reduce exposure. Consult product documentation for specific instructions on disabling or configuring the libwebsockets SSH Protocol Handler within your Red Hat product.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-22T00:00:00Z",
    "bugzilla": {
      "description": "bind: bind9: Incorrect acceptance of NSEC3 records",
      "id": "2504560",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2504560"
    },
    "cvss3": {
      "cvss3_base_score": "6.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-345",
    "details": [
      "BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses.\nThis issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
      "BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses."
    ],
    "statement": "This Moderate flaw in BIND allows an attacker to forge authenticated NXDOMAIN responses for sibling zones due to incorrect validation of child-zone NSEC3 records. Exploitation requires high attack complexity, limiting the immediate risk to Red Hat products.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55437",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "bind-32:9.18.33-15.el10_2.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54509",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "bind9.16-32:9.16.23-0.22.el8_10.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54654",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "bind-32:9.11.36-16.el8_10.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54654",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "bind-32:9.11.36-16.el8_10.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54510",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "bind-32:9.16.23-40.el9_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55442",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "bind9.18-32:9.18.29-14.el9_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57189",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "bind-32:9.16.23-18.el9_4.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55441",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "bind-32:9.16.23-31.el9_6.4"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54071",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "bind-main-9.20.26-0.1.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "dhcp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-10723\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-10723"
    ],
    "name": "CVE-2026-10723",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-04T00:00:00Z",
    "bugzilla": {
      "description": "NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend",
      "id": "2484613",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484613"
    },
    "cvss3": {
      "cvss3_base_score": "6.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-78",
    "details": [
      "A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.",
      "A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager."
    ],
    "statement": "This Moderate local privilege escalation flaw in NetworkManager's dhclient backend is not exploitable in default Red Hat Enterprise Linux configurations. Exploitation requires an administrator to explicitly configure NetworkManager to use `dhclient` instead of its default internal DHCP client, allowing a local user to escalate privileges via a crafted MUD URL.",
    "acknowledgement": "Red Hat would like to thank Andrej Tomci for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58555",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "NetworkManager-1:1.40.16-21.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58555",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "NetworkManager-1:1.40.16-21.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58572",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "NetworkManager-1:1.54.3-5.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58572",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "NetworkManager-1:1.54.3-5.el9_8"
      }
    ],
    "package_state": [
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Fix deferred",
        "package_name": "multicluster-engine/cluster-api-provider-aws-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "mobile-broadband-provider-info",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "network-manager-applet",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager-libreswan",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager-openswan",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager-libreswan",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager-libreswan",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mobile-broadband-provider-info",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "network-manager-applet",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager-libreswan",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
        "fix_state": "Fix deferred",
        "package_name": "networkmanager",
        "cpe": "cpe:/a:redhat:jbosseapxp"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/kubernetes-nmstate-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/kubernetes-nmstate-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-aws-cluster-api-controllers-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-aws-cluster-api-controllers-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-kubernetes-nmstate-handler-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-kubernetes-nmstate-handler-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-ovn-kubernetes-microshift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-ovn-kubernetes-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/art-images",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-10805\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-10805"
    ],
    "name": "CVE-2026-10805",
    "mitigation": {
      "value": "To prevent exploitation, ensure NetworkManager is not configured to use the `dhclient` backend. The default configuration on Red Hat Enterprise Linux does not enable `dhclient`. If a custom configuration file, such as `/etc/NetworkManager/conf.d/00-dhcp.conf`, contains `[main] dhcp=dhclient`, remove or comment out this line. After modifying the configuration, restart the NetworkManager service: `sudo systemctl restart NetworkManager` Warning: Restarting the NetworkManager service will temporarily disrupt network connectivity.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-10T06:37:59Z",
    "bugzilla": {
      "description": "ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching",
      "id": "2487437",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487437"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-940",
    "details": [
      "NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.",
      "A flaw was found in ldns. When applications use ldns as a resolver over User Datagram Protocol (UDP), it fails to properly match the query's destination address and port with the response's source address and port. Additionally, the query ID and question are not matched with the response. This vulnerability allows a remote attacker to perform off-path poisoning attacks, potentially leading to DNS cache poisoning and redirection to malicious resources."
    ],
    "statement": "This Important flaw in ldns, when utilized as a UDP stub resolver, allows remote attackers to conduct off-path DNS poisoning attacks. The vulnerability stems from insufficient validation of DNS query and response parameters, including destination/source addresses, ports, query IDs, and questions. This can lead to DNS cache poisoning, potentially redirecting users to malicious resources.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49836",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "ldns-0:1.8.3-18.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53402",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "ldns-0:1.8.3-18.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49520",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "ldns-0:1.7.0-23.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50108",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "ldns-0:1.7.1-12.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54377",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "ldns-0:1.7.1-11.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54244",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "ldns-0:1.7.1-11.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54254",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "ldns-0:1.7.1-12.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "ExternalDNS Operator",
        "fix_state": "Not affected",
        "package_name": "edo/external-dns-rhel8",
        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
      },
      {
        "product_name": "ExternalDNS Operator",
        "fix_state": "Not affected",
        "package_name": "edo/external-dns-rhel9",
        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "ldns",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "ldns",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4",
        "impact": "important"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/traefik-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-10846\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-10846\nhttps://www.nlnetlabs.nl/downloads/ldns/CVE-2026-10846.txt"
    ],
    "name": "CVE-2026-10846",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-05T14:30:58Z",
    "bugzilla": {
      "description": "perl-DBI: perl-DBI: Heap overflow in SQL preparsing can lead to denial of service or arbitrary code execution.",
      "id": "2485464",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485464"
    },
    "cvss3": {
      "cvss3_base_score": "7.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders.\nThe preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer.  Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.",
      "A flaw was found in perl-DBI. A heap overflow vulnerability exists when preparsing SQL statements with more than 9 binders. The `preparse` method incorrectly allocates buffer space for SQL placeholder characters, leading to an overflow when processing binders with two or more digits. This can result in a denial of service or potentially arbitrary code execution."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38513",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "perl-DBI-0:1.643-26.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38901",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "perl-DBI:1.641-8100020260624081239.69ef70f8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38512",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "perl-DBI-0:1.643-9.el9_8.1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-10879\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-10879\nhttps://github.com/perl5-dbi/dbi/commit/af79036c07aa9a457971c0f4136e37c85dc20978.patch\nhttps://metacpan.org/release/HMBRAND/DBI-1.648/changes"
    ],
    "name": "CVE-2026-10879",
    "csaw": false
  },
  {
    "threat_severity": "Critical",
    "public_date": "2026-06-14T11:39:21Z",
    "bugzilla": {
      "description": "perl-GD: perl-GD: Arbitrary command execution and file overwrite via crafted filenames",
      "id": "2488744",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488744"
    },
    "cvss3": {
      "cvss3_base_score": "9.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-78",
    "details": [
      "GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle.\nGD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe (\"| cmd\", \"cmd |\") or begins with a redirect (\"> path\", \">> path\") is run as a command or redirect rather than opened as a file. _make_filehandle is the single open path behind every filename-accepting constructor (new, newFromPng, newFromJpeg, and the rest); the in-memory *Data variants do not open a path and are unaffected.\nAny caller that forwards untrusted input to one of these constructors as a pathname can run an arbitrary command or truncate a file under the process UID.",
      "A flaw was found in perl-GD. A remote attacker could exploit this vulnerability by providing specially crafted filenames to functions that open files. This issue arises because the `_make_filehandle` function uses Perl's 2-argument `open()` with untrusted input, allowing special characters like pipes or redirects to be interpreted as commands or file operations. Successful exploitation could lead to arbitrary command execution or unauthorized file modification under the privileges of the affected process."
    ],
    "statement": "This Critical vulnerability in `perl-GD` enables arbitrary command execution or file overwrites when applications process untrusted input as filenames for image constructors. Exploitation occurs if an application passes a specially crafted filename containing pipe or redirect characters, allowing an attacker to execute commands or modify files with the privileges of the affected process. This poses a significant risk to system integrity and confidentiality in environments where `perl-GD` is used to handle external, unsanitized file paths.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49758",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "perl-GD-0:2.49-3.el7_9.1",
        "impact": "critical"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "perl-GD",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "critical"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-11526\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-11526\nhttps://github.com/lstein/Perl-GD/commit/67b163713c6c78dfeb693da0978ae934e5cd8210.patch\nhttps://metacpan.org/release/RURBAN/GD-2.86/changes"
    ],
    "name": "CVE-2026-11526",
    "mitigation": {
      "value": "Exploitation of CGI scripts using perl-GD is made difficult with the use of `SecRuleEngine On` from the `mod_security` RPM. See https://access.redhat.com/solutions/6961459 for details on installing `mod_security` on RHEL.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-14T11:40:45Z",
    "bugzilla": {
      "description": "Config-Inifiles: Config::IniFiles: OS command injection and file overwrite via untrusted file argument",
      "id": "2488743",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488743"
    },
    "cvss3": {
      "cvss3_base_score": "8.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-78",
    "details": [
      "Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle.\nConfig::IniFiles::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe (\"| cmd\", \"cmd |\") or begins with a redirect (\"> path\", \">> path\") is run as a command or redirect rather than opened as a file. The helper is the open path behind the documented -file argument: new(-file => $thing) reaches it through ReadConfig. An in-memory scalar reference (-file => \\$text) does not open a path and is unaffected.\nAny caller that forwards untrusted input to the -file argument can run an arbitrary command or truncate a file under the process UID.",
      "A flaw was found in Config::IniFiles. This vulnerability allows an attacker to achieve OS command injection or overwrite files. By supplying untrusted input to the -file argument, an attacker can execute arbitrary commands or truncate files under the privileges of the application. This occurs because the _make_filehandle function misinterprets specially crafted filenames as system commands or file redirection operations."
    ],
    "statement": "No Red Hat product ships an exploitable instance of Config::IniFiles. The matching RPM (perl-Config-IniFiles) is present only in the optional, disabled-by-default CodeReady Linux Builder (CRB) repositories for RHEL 8 and RHEL 9 as a build-time dependency, and is never invoked with attacker-controlled -file input by Red Hat's build process. The EPEL package already ships the fixed version (3.001000). Only the Fedora package remains on a pre-fix version; that is delegated to Fedora's own security response.",
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-11527\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-11527\nhttps://github.com/shlomif/perl-Config-IniFiles/commit/3e48f9627fbba4dae5de35be1f735cdeb7e47fb8.patch\nhttps://metacpan.org/release/SHLOMIF/Config-IniFiles-3.001000/changes"
    ],
    "name": "CVE-2026-11527",
    "mitigation": {
      "value": "Users on Fedora (or any pre-fix build) should avoid passing untrusted input to Config::IniFiles->new(-file => ...). Passing an in-memory scalar reference instead (-file => \\$text) does not invoke the vulnerable code path and is unaffected. Upgrade to Config::IniFiles 3.001000+ once available.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-22T00:00:00Z",
    "bugzilla": {
      "description": "bind: bind9: Potential memory usage beyond configured limits",
      "id": "2504298",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2504298"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-400",
    "details": [
      "A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
      "A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the max-cache-size parameter"
    ],
    "statement": "This Important flaw in BIND's DNSSEC-validating resolver can lead to a denial of service. An attacker can trigger excessive memory usage by performing a random subdomain attack against a DNSSEC-signed zone, causing the resolver to exceed its `max-cache-size` limits. This is critical for Red Hat deployments where BIND is configured for DNSSEC validation and exposed to untrusted query sources.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55437",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "bind-32:9.18.33-15.el10_2.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54509",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "bind9.16-32:9.16.23-0.22.el8_10.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54654",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "bind-32:9.11.36-16.el8_10.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54654",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "bind-32:9.11.36-16.el8_10.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54510",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "bind-32:9.16.23-40.el9_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55442",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "bind9.18-32:9.18.29-14.el9_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57189",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "bind-32:9.16.23-18.el9_4.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55441",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "bind-32:9.16.23-31.el9_6.4"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54071",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "bind-main-9.20.26-0.1.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "dhcp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-11622\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-11622"
    ],
    "name": "CVE-2026-11622",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-22T00:00:00Z",
    "bugzilla": {
      "description": "bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards",
      "id": "2504338",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2504338"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-345",
    "details": [
      "It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default).\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
      "It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes named to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set synth-from-dnssec yes; (which is the default)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55437",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "bind-32:9.18.33-15.el10_2.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54509",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "bind9.16-32:9.16.23-0.22.el8_10.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54654",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "bind-32:9.11.36-16.el8_10.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54654",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "bind-32:9.11.36-16.el8_10.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54510",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "bind-32:9.16.23-40.el9_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55442",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "bind9.18-32:9.18.29-14.el9_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57189",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "bind-32:9.16.23-18.el9_4.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55441",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "bind-32:9.16.23-31.el9_6.4"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54071",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "bind-main-9.20.26-0.1.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "dhcp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-11721\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-11721"
    ],
    "name": "CVE-2026-11721",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-09T19:08:31Z",
    "bugzilla": {
      "description": "sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data",
      "id": "2487258",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487258"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.",
      "A flaw was found in SQLite's FTS5 full-text search extension. This vulnerability involves memory corruption, specifically an out-of-bounds read and a heap buffer overflow, which can be triggered by supplying a crafted database with malformed FTS5 page data. When an FTS5 MATCH query is executed against such a database, an attacker can cause process crashes, memory exhaustion, or achieve arbitrary code execution, potentially compromising the system."
    ],
    "statement": "Important: This flaw in the SQLite FTS5 full-text search extension can lead to arbitrary code execution or denial of service. Exploitation requires an application to process a specially crafted SQLite database containing malformed FTS5 page data, which could occur if an attacker provides a malicious database to a vulnerable application. This risk is elevated in scenarios where applications handle untrusted SQLite database files.",
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Affected",
        "package_name": "exploit-intelligence-tech-preview/agent-client-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "mingw-sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "nodejs:22/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "nodejs:24/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "rust-toolset:rhel8/rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "nodejs:22/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "nodejs:24/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Affected",
        "package_name": "sqlite",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cuda-12.9-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cuda-13.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-neuron-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-6.4-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-7.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-7.1-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-spyre-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-tpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ai-gateway-payload-processing-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-automl-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-autorag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-codeflare-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-argoexec-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-data-science-pipelines-operator-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-eval-hub-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-feast-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-fms-guardrails-orchestrator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kf-notebook-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kserve-autogluon-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kserve-llmisvc-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kube-auth-proxy-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kuberay-operator-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kueue-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llama-stack-k8s-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llm-d-inference-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llm-d-kv-cache-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llm-d-routing-sidecar-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-maas-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-maas-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-mlflow-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-launcher-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mlserver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mm-rest-proxy-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-automl-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-autorag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-eval-hub-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-gen-ai-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-maas-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-modelmesh-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-modelmesh-serving-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-metadata-collection-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-performance-data-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-serving-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-notebook-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipelines-components-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-rhaii-cluster-validator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-rhaii-validator-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-spark-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trainer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-training-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-service-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-service-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workload-variant-autoscaler-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/rhai-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-11822\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-11822\nhttps://sqlite.org/releaselog/3_53_2.html\nhttps://sqlite.org/src/info/061febcf41ca\nhttps://sqlite.org/src/info/4a5ad516ea93\nhttps://www.vulncheck.com/advisories/sqlite-before-memory-corruption-in-fts5-extension"
    ],
    "name": "CVE-2026-11822",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-09T19:21:42Z",
    "bugzilla": {
      "description": "sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5",
      "id": "2487269",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487269"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-191",
    "details": [
      "SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.",
      "A flaw was found in SQLite, specifically within its FTS5 full-text search extension. Attackers can exploit a heap-based buffer overflow by providing a specially crafted database. This crafted database contains malicious metadata that triggers an integer underflow during FTS5 MATCH query processing. Successful exploitation of this vulnerability can lead to a crash of the application or allow for arbitrary code execution."
    ],
    "statement": "This Important vulnerability in SQLite's FTS5 full-text search extension can lead to arbitrary code execution or application crashes due to a heap-based buffer overflow. Exploitation requires an attacker to provide a specially crafted SQLite database, which must then be processed by an application compiled with FTS5 support. While requiring user interaction and local access, the potential for full impact on system resources justifies the Important severity.",
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Affected",
        "package_name": "exploit-intelligence-tech-preview/agent-client-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "mingw-sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "nodejs:22/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "nodejs:24/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "rust-toolset:rhel8/rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "nodejs:22/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "nodejs:24/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "sqlite",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Affected",
        "package_name": "sqlite",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cuda-12.9-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cuda-13.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-neuron-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-6.4-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-7.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-7.1-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-spyre-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-tpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ai-gateway-payload-processing-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-automl-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-autorag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-codeflare-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-argoexec-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-data-science-pipelines-operator-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-eval-hub-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-feast-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-fms-guardrails-orchestrator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kf-notebook-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-autogluon-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kserve-llmisvc-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kube-auth-proxy-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kuberay-operator-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kueue-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llama-stack-k8s-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llm-d-inference-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llm-d-kv-cache-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llm-d-routing-sidecar-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-maas-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-maas-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-mlflow-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-launcher-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mlserver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mm-rest-proxy-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-automl-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-autorag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-eval-hub-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-gen-ai-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-maas-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-modelmesh-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-modelmesh-serving-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-metadata-collection-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-performance-data-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-serving-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-notebook-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipelines-components-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-rhaii-cluster-validator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-rhaii-validator-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-spark-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trainer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-training-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-service-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-service-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workload-variant-autoscaler-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/rhai-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-11824\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-11824\nhttps://sqlite.org/releaselog/3_53_2.html\nhttps://sqlite.org/src/info/061febcf41ca\nhttps://sqlite.org/src/info/4a5ad516ea93\nhttps://www.vulncheck.com/advisories/sqlite-before-heap-buffer-overflow-via-fts5-fts5chunkiterate"
    ],
    "name": "CVE-2026-11824",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-23T22:02:45Z",
    "bugzilla": {
      "description": "python: Python tarfile module: Denial of Service via improper EOF handling in streaming mode",
      "id": "2492050",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492050"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-835",
    "details": [
      "When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.",
      "A flaw was found in the Python `tarfile` module. When processing a specially crafted tar archive opened in 'streaming mode' (mode='r|'), the module does not properly handle the end-of-file (EOF) condition. This can cause the `tarfile` module to enter an infinite loop, leading to a Denial of Service (DoS) for applications processing such archives."
    ],
    "statement": "A flaw was found in the Python tarfile module. When processing a tar archive in streaming mode (mode='r|'), the _Stream.seek function does not properly check for end-of-file, which can cause an infinite loop when processing a specially crafted archive. Red Hat ships Python as part of many products, and applications using tarfile's streaming mode are potentially affected by this denial of service vulnerability.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-05T00:00:00Z",
        "advisory": "RHSA-2026:35806",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-14-main-3.14.6-1.2.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-05T00:00:00Z",
        "advisory": "RHSA-2026:35807",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-11-main-3.11.15-4.4.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-05T00:00:00Z",
        "advisory": "RHSA-2026:35812",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-13-main-3.13.14-1.2.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-05T00:00:00Z",
        "advisory": "RHSA-2026:35813",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-12-main-3.12.13-3.3.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54534",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-14-main-3.14.7-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54554",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-13-main-3.13.15-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Fix deferred",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python3.12",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python3.14",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3.12",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.12",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.14",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.9",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-cuda-12.9-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-cuda-13.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-neuron-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-rocm-6.4-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-rocm-7.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-rocm-7.1-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-spyre-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-tpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-automl-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-autorag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-nlp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-tgis-serving-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-autogluon-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llm-d-inference-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llm-d-kv-cache-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlserver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipelines-components-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-spark-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ta-lmes-job-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda121-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda124-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda128-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda128-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Fix deferred",
        "package_name": "container-native-virtualization/ocp-virt-validation-checkup-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Self-service automation portal 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/bootc-automation-portal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_portal:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-11972\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-11972\nhttps://github.com/python/cpython/issues/151981\nhttps://github.com/python/cpython/pull/151982\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"
    ],
    "name": "CVE-2026-11972",
    "mitigation": {
      "value": "Avoid using tarfile streaming mode (mode='r|') with untrusted tar archives. Use the standard file-based mode (mode='r') instead where possible.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-29T13:21:42Z",
    "bugzilla": {
      "description": "libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow",
      "id": "2494191",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494191"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.\nBy supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame.\nSuccessful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.\nThis issue has been fixed in the commit c2e233fc.\nNOTE:\nThe maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.",
      "A flaw was found in libxml2, specifically within the xmlcatalog utility when operating in shell mode. An attacker can exploit multiple stack-based buffer overflows by providing an excessively long input line. This leads to memory corruption, which may cause the application to crash or potentially allow the attacker to execute arbitrary code within the context of the xmlcatalog process."
    ],
    "statement": "This Moderate impact flaw in libxml2 affects the `xmlcatalog` utility when operating in `--shell` mode. Exploitation requires an attacker to provide specially crafted, excessively long input, leading to stack-based buffer overflows. This vulnerability is limited to scenarios where an attacker can control input to the `xmlcatalog` utility, reducing its overall exposure in typical Red Hat deployments.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33840",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libxml2-main-2.15.3-0.1.1.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "libxml2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "libxml2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libxml2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libxml2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libxml2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-11979\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-11979\nhttps://cert.pl/en/posts/2026/06/CVE-2026-11979\nhttps://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e"
    ],
    "name": "CVE-2026-11979",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-15T21:11:09Z",
    "bugzilla": {
      "description": "perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read",
      "id": "2489066",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2489066"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "Socket versions before 2.041 for Perl have an out-of-bounds heap read.\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.",
      "A flaw was found in the `perl-Socket` component. The `pack_ip_mreq_source()` function, which handles network socket operations, contains an out-of-bounds heap read vulnerability. An attacker providing a specially crafted input can cause the system to read beyond the intended memory buffer, potentially leading to information disclosure from adjacent memory regions."
    ],
    "statement": "A flaw was found in the Perl Socket module's pack_ip_mreq_source() function. An incorrect length validation may allow an out-of-bounds heap read, potentially exposing up to a few bytes of adjacent memory. Successful exploitation requires an application to call the affected function with attacker-controlled input, which limits the practical impact to information disclosure.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11342",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "perl-socket-main-2.041-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "perl-Socket",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "perl-Socket6",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "perl-Socket6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "perl-Socket",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "perl-Socket6",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "perl-Socket",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "perl-Socket6",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "perl-Socket",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "perl-Socket6",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-12087\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-12087\nhttps://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch\nhttps://metacpan.org/release/PEVANS/Socket-2.041/changes"
    ],
    "name": "CVE-2026-12087",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-24T00:00:00Z",
    "bugzilla": {
      "description": "librenswan: IKEv2 Denial of Service via malformed fragmentation",
      "id": "2494149",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494149"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-193",
    "details": [
      "An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.",
      "A flaw was found in Libreswan's IKEv2 fragment reassembly mechanism. When a VPN gateway processes incoming split network packets (fragments) containing unexpected data, an off-by-one boundary validation error triggers an internal program safety check (assertion failure). A remote, unauthenticated attacker can exploit this by sending a specific sequence of malformed IKEv2 fragments to an exposed gateway, causing the Libreswan daemon to immediately crash and restart. While this flaw does not allow data theft or unauthorized system access, a continuous stream of these packets will lead to a persistent Denial of Service (DoS) for legitimate VPN users."
    ],
    "statement": "Red Hat Product Security rates this vulnerability as having an Important impact, primarily because it can be exploited remotely without authentication. However, the actual exposure depends entirely on your specific VPN configuration:\n```\nAffected Configurations: This vulnerability only impacts IKEv2 connections. By default, Libreswan enables packet fragmentation (fragmentation=yes) to handle large encryption keys over restrictive network paths. Any default IKEv2 tunnel that do not set fragmentation=no are vulnerable.\nUnaffected Configurations: IKEv1 connections are completely unaffected by this flaw.\n```\n```\nCrucially, this vulnerability does not impact environments running Libreswan versions 4.5 and older. The vulnerable fragment reassembly engine was introduced during a major codebase refactor in version 4.6. As a result, older product branches—such as those shipped in rhel-6, rhel-7, rhel-8.6.z and prior do not contain the flawed code path and are inherently immune to this attack.\n```",
    "affected_release": [
      {
        "product_name": "Fast Datapath for Red Hat Enterprise Linux 9",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46986",
        "cpe": "cpe:/o:redhat:enterprise_linux:9::fastdatapath",
        "package": "libreswan-0:5.3.2-1.el9fdp"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46398",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libreswan-0:5.3.2-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55449",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libreswan-0:5.2-1.el10_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46396",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libreswan-0:4.12-2.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46397",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libreswan-0:4.15-10.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57741",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libreswan-0:4.15-8.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "libreswan",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "libreswan",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "libreswan",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-12413\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-12413\nhttps://libreswan.org/security/CVE-2026-12413/\nhttps://libreswan.org/security/CVE-2026-12413/CVE-2026-12413.txt\nhttps://lists.libreswan.org/archives/list/swan-announce@lists.libreswan.org/thread/7BZBYREBGXFPS4TSWOZX37WABRZVLK74/"
    ],
    "name": "CVE-2026-12413",
    "mitigation": {
      "value": "If upgrading to Libreswan is not an option, you can mitigate the vulnerability by disabling IKEv2 fragment processing:\nAdd the following directive to your global or connection-specific configuration files in /etc/ipsec.conf: ```fragmentation=no```\nWarning: Disabling fragmentation may cause larger IKEv2 payloads (such as those carrying large X.509 certificate chains) to be dropped by intermediate network routers if they exceed the path MTU.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-27T00:00:00Z",
    "bugzilla": {
      "description": "libsoup: Incomplete fix for CVE-2026-0716: Out-of-bounds read in libsoup WebSocket frame processing (unmasked path)",
      "id": "2489655",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2489655"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB read in a libsoup-based client when max_incoming_payload_size is set to 0.",
      "The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB read in a libsoup-based client when max_incoming_payload_size is set to 0."
    ],
    "statement": "This vulnerability is rated Moderate for Red Hat because it requires a non-default configuration where max_incoming_payload_size is explicitly set to 0 or unset in libsoup's WebSocket frame processing. In typical Red Hat deployments, this configuration is not enabled by default, limiting the exposure to memory disclosure or application instability.",
    "acknowledgement": "Red Hat would like to thank Adel Bouachraoui and Gerard Capdevila for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libsoup3",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-12478\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-12478\nhttps://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/518"
    ],
    "name": "CVE-2026-12478",
    "mitigation": {
      "value": "To mitigate this issue, applications utilizing libsoup's WebSocket support should ensure that the `max_incoming_payload_size` is explicitly set to a non-zero value. This prevents the library from processing WebSocket frames with an unset or zero maximum payload size, which can lead to out-of-bounds reads. Consult application-specific documentation for configuring libsoup parameters.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-16T00:00:00Z",
    "bugzilla": {
      "description": "cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall",
      "id": "2489805",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2489805"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-250",
    "details": [
      "A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.",
      "A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system."
    ],
    "statement": "This vulnerability affects the cifs.upcall helper in cifs-utils. Red Hat Product Security has assessed this issue as an Important severity vulnerability.\nThe flaw occurs because cifs.upcall performs user and group resolution operations after entering attacker-controlled namespaces but before fully dropping its elevated privileges. A local attacker may abuse this behavior to influence NSS module loading and execute arbitrary code with root privileges.\nSuccessful exploitation requires local access to the system and several environmental conditions, including registration of the cifs.spnego key type, the presence of the cifs-utils request-key rule, and the ability to create unprivileged user namespaces. However, once these conditions are met, exploitation may allow a local user to obtain root privileges.\n```\nThe issue has been fixed by upstream in cifs-utils v7.6\n```",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32990",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "cifs-utils-0:7.6-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39575",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "cifs-utils-0:7.0-5.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39576",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "cifs-utils-0:7.6-2.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39576",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "cifs-utils-0:7.6-2.el9_8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:44232",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202607220526-0"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "cifs-utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "cifs-utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-12505\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-12505\nhttps://git.samba.org/?p=cifs-utils.git;a=commit;h=972c5b5ff95e3e812bc8daa72d0383654ab0dba7"
    ],
    "name": "CVE-2026-12505",
    "mitigation": {
      "value": "Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-09T12:00:00Z",
    "bugzilla": {
      "description": "sssd: Use-after-free crash in SSSD' 'sssd_pam' process",
      "id": "2490288",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490288"
    },
    "cvss3": {
      "cvss3_base_score": "6.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.",
      "A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit."
    ],
    "statement": "This Moderate impact use-after-free flaw in the SSSD PAM responder can lead to a denial of service during YubiKey authentication, causing the process to crash and disrupt user access. While there is a theoretical potential for privilege escalation, exploitation is considered difficult due to the specific conditions required, which involve an attacker controlling smartcard contents during an active authentication attempt.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "pam",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "sssd",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "pam",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "sssd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "pam",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "sssd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "pam",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "sssd",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "pam",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "sssd",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "pam",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-12610\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-12610\nhttps://github.com/SSSD/sssd/issues/8796"
    ],
    "name": "CVE-2026-12610",
    "mitigation": {
      "value": "Configure the sssd systemd service to automatically restart on failure. This ensures authentication remains available even if an attacker triggers the denial-of-service crash.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T21:14:00Z",
    "bugzilla": {
      "description": "dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported DS/DNSKEY replies",
      "id": "2490763",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490763"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-122",
    "details": [
      "A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and\nquery logging are both enabled, logging of DS or DNSKEY replies containing\nunsupported algorithm or digest types can cause dnsmasq to write past the end\nof an internal logging buffer. A remote attacker able to supply such a DNS\nresponse may crash the dnsmasq process, resulting in denial of service.",
      "A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and\nquery logging are both enabled, logging of DS or DNSKEY replies containing\nunsupported algorithm or digest types can cause dnsmasq to write past the end\nof an internal logging buffer. A remote attacker able to supply such a DNS\nresponse may crash the dnsmasq process, resulting in denial of service."
    ],
    "statement": "Red Hat Product Security rates this issue as Moderate. The overflow occurs in\nthe query logging path only, requires both DNSSEC validation and query logging\nto be enabled, involves a bounded overwrite with non-attacker-controlled data,\nand is most appropriately characterized as a denial of service rather than a\nconfidentiality, integrity, or code execution issue. This assessment is\nconsistent with the upstream maintainer's analysis.",
    "acknowledgement": "Red Hat would like to thank Yiwei Hou (UC Berkeley) for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-12725\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-12725"
    ],
    "name": "CVE-2026-12725",
    "mitigation": {
      "value": "Mitigate this issue by updating to a version of dnsmasq that includes the\nupstream fix (commit 36d081e37477027fd721fea498f3760f529034ad), or by\ndisabling query logging if DNSSEC validation must remain enabled. After\nchanging the configuration, restart the dnsmasq service for the changes to\ntake effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-16T00:00:00Z",
    "bugzilla": {
      "description": "libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image",
      "id": "2492871",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492871"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-122",
    "details": [
      "A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).",
      "A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS)."
    ],
    "statement": "This is an Important heap-based buffer overflow in libtiff affecting applications that explicitly configure the library to decode Pixarlog-compressed TIFF images using the PIXARLOGDATAFMT_8BITABGR output format with SamplesPerPixel == 3. Standard image reading functions, such as TIFFReadRGBAImage, are not directly impacted as they do not typically select this specific format. Exploitation requires processing a specially crafted TIFF image under these specific conditions.",
    "acknowledgement": "Red Hat would like to thank Ariel Schön for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41892",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libtiff-0:4.6.0-8.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49671",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libtiff-0:4.6.0-6.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:47183",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "compat-libtiff3-0:3.9.4-16.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:47184",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libtiff-0:4.0.9-38.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54642",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "compat-libtiff3-0:3.9.4-13.el8_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54642",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "compat-libtiff3-0:3.9.4-13.el8_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54640",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "compat-libtiff3-0:3.9.4-13.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58545",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libtiff-0:4.0.9-21.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54640",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "compat-libtiff3-0:3.9.4-13.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58545",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libtiff-0:4.0.9-21.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54638",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "compat-libtiff3-0:3.9.4-13.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58553",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libtiff-0:4.0.9-29.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54638",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "compat-libtiff3-0:3.9.4-13.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58553",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libtiff-0:4.0.9-29.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42668",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libtiff-0:4.4.0-18.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58554",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libtiff-0:4.4.0-8.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58556",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "libtiff-0:4.4.0-12.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50774",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libtiff-0:4.4.0-13.el9_6.6"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34890",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libtiff-main-4.7.1-2.4.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libtiff",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "compat-libtiff3",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "libtiff",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "mingw-libtiff",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "boost",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-12912\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-12912\nhttps://gitlab.com/libtiff/libtiff/-/merge_requests/873\nhttps://gitlab.com/libtiff/libtiff/-/work_items/824"
    ],
    "name": "CVE-2026-12912",
    "mitigation": {
      "value": "To mitigate this issue, applications processing untrusted TIFF images should avoid explicitly configuring `PIXARLOGDATAFMT_8BITABGR` when decoding PixarLog-compressed TIFF images with three samples per pixel. This specific combination of output format and samples per pixel is required to trigger the heap-based buffer overflow.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-22T00:00:00Z",
    "bugzilla": {
      "description": "bind: bind9: Unexpected exit with NSEC and NSEC3 both present",
      "id": "2504447",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2504447"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-617",
    "details": [
      "If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
      "If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55437",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "bind-32:9.18.33-15.el10_2.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54509",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "bind9.16-32:9.16.23-0.22.el8_10.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54654",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "bind-32:9.11.36-16.el8_10.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54654",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "bind-32:9.11.36-16.el8_10.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54510",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "bind-32:9.16.23-40.el9_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55442",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "bind9.18-32:9.18.29-14.el9_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57189",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "bind-32:9.16.23-18.el9_4.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55441",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "bind-32:9.16.23-31.el9_6.4"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54071",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "bind-main-9.20.26-0.1.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "dhcp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-13204\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-13204"
    ],
    "name": "CVE-2026-13204",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-22T00:00:00Z",
    "bugzilla": {
      "description": "bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field",
      "id": "2504166",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2504166"
    },
    "cvss3": {
      "cvss3_base_score": "8.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
      "status": "verified"
    },
    "details": [
      "The BIND resolver accepts validly-signed NSEC records where the \"Next Domain Name\" field points outside the signer's zone.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
      "The BIND resolver accepts validly-signed NSEC records where the \"Next Domain Name\" field points outside the signer's zone."
    ],
    "statement": "An attacker controlling any DNSSEC-signed zone can craft NSEC records that span into victim zones, enabling cross-zone cache poisoning with authenticated denial-of-service responses (AD=1).",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55437",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "bind-32:9.18.33-15.el10_2.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54509",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "bind9.16-32:9.16.23-0.22.el8_10.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54654",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "bind-32:9.11.36-16.el8_10.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54654",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "bind-32:9.11.36-16.el8_10.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54510",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "bind-32:9.16.23-40.el9_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55442",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "bind9.18-32:9.18.29-14.el9_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57189",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "bind-32:9.16.23-18.el9_4.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55441",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "bind-32:9.16.23-31.el9_6.4"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54071",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "bind-main-9.20.26-0.1.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "dhcp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-13321\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-13321"
    ],
    "name": "CVE-2026-13321",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-07T00:00:00Z",
    "bugzilla": {
      "description": "util-linux: util-linux: heap use-after-free in libblkid nested partition probing",
      "id": "2494101",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494101"
    },
    "cvss3": {
      "cvss3_base_score": "6.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-416",
    "details": [
      "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
      "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."
    ],
    "statement": "This Moderate severity heap use-after-free flaw in libblkid of util-linux could allow an attacker with local access to a system to cause a denial of service or potentially disclose limited information. The vulnerability is triggered when processing a specially crafted block device image, which libblkid automatically handles as root during hot-plug events via udev/udisks. This makes systems susceptible if untrusted block devices can be introduced.",
    "acknowledgement": "Red Hat would like to thank Thai Duong (Calif.io in collaboration with Claude and Anthropic Research) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26573",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "util-linux-main-2.42.2-1.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "util-linux",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "util-linux",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "util-linux",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "util-linux",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-13595\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-13595\nhttps://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
    ],
    "name": "CVE-2026-13595",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-07T00:00:00Z",
    "bugzilla": {
      "description": "yelp: yelp-xsl: Overly Permissive Content Security Policy in Yelp Allows Host File Disclosure from Flatpak Applications",
      "id": "2494110",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494110"
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-693",
    "details": [
      "A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.",
      "A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information."
    ],
    "statement": "This vulnerability affects the Content Security Policy (CSP) implementation handling help documents rendered outside the application container via the Flatpak OpenURI portal. Red Hat Product Security has rated this issue as Important.\nThe flaw is caused by an overly permissive Content Security Policy (CSP) implementation that allows attacker-controlled help content to bypass Flatpak's intended sandbox isolation. A malicious Flatpak application can invoke Yelp through the standard OpenURI portal and supply crafted help content that causes the application to access and disclose arbitrary user-readable files from the host system.\nUnlike typical local file disclosure vulnerabilities, exploitation does not require privileges on the vulnerable Yelp application itself. A malicious Flatpak application can invoke Yelp through the standard OpenURI portal without requiring additional authorization or user interaction beyond running the application. Because the vulnerability enables a sandboxed Flatpak application to access resources outside its intended security boundary by leveraging the host's Yelp application, Red Hat Product Security considers this a cross-boundary information disclosure vulnerability. Under these conditions, an attacker may disclose arbitrary user-readable files from the host system. The currently available analysis does not demonstrate impacts to integrity or availability.\n```\nThis flaw arises as an upstream regression that reintroduced part of the functionality previously addressed by CVE-2025-3155.\nThe original upstream remediation for CVE-2025-3155 required coordinated changes in both the yelp application and the yelp-xsl stylesheet package. Red Hat Enterprise Linux streams that previously received backported fixes for CVE-2025-3155 are also affected by this regression.\nFor CVE-2026-13601, upstream has chosen to remediate the remaining vulnerability entirely within the yelp application. Consequently, this issue is remediated exclusively through security updates to the yelp package, and no additional updates to yelp-xsl are required for this CVE. Systems are fully protected once the corresponding yelp security update has been applied.\nHence, Red Hat Enterprise Linux is only required to update \"yelp\" package to get the fix.\nAlthough RHEL 10 and RHIVOS ship versions of yelp-xsl, the yelp application is not shipped or supported on those platforms. As a result, the vulnerable execution path is not present and those products are not affected.\n```",
    "acknowledgement": "Red Hat would like to thank Codean Labs for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57417",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "yelp-2:3.28.1-2.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:47177",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "yelp-2:3.28.1-3.el8_10.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54605",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "yelp-2:3.28.1-3.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54605",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "yelp-2:3.28.1-3.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54666",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "yelp-2:3.28.1-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54666",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "yelp-2:3.28.1-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54624",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "yelp-2:3.28.1-3.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54624",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "yelp-2:3.28.1-3.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:47178",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "yelp-2:40.3-3.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54637",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "yelp-2:40.3-2.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54540",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "yelp-2:40.3-2.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54539",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "yelp-2:40.3-2.el9_6.2"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "yelp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-13601\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-13601\nhttps://blogs.gnome.org/mcatanzaro/2026/05/11/flatpak-sandbox-escape-via-yelp/\nhttps://gitlab.gnome.org/GNOME/yelp/-/commit/c8c8244c8a812860782d635890c9b6c43ecc2639\nhttps://gitlab.gnome.org/GNOME/yelp/-/work_items/238"
    ],
    "name": "CVE-2026-13601",
    "mitigation": {
      "value": "No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the appropriate security update when they becomes available.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-28T12:34:00Z",
    "bugzilla": {
      "description": "GraphicsMagick: GraphicsMagick: Memory corruption via crafted Photo CD (PCD) file",
      "id": "2494107",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494107"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "A flaw was found in GraphicsMagick's Photo CD (PCD) decoder. A remote attacker could exploit this vulnerability by providing a specially crafted PCD file. This could lead to an out-of-bounds write, corrupting memory and potentially causing a denial of service or other unpredictable system behavior."
    ],
    "statement": "This Important flaw in GraphicsMagick's PCD decoder allows an out-of-bounds write when processing a specially crafted PCD file under specific decoding conditions, such as a page/subimage index of 4 or higher, or a size hint of 1536x1024 or greater. This could lead to heap corruption and potentially arbitrary code execution, impacting applications that process untrusted PCD image files.",
    "acknowledgement": "Red Hat would like to thank Shubham Raj (Causal Security (https://causalsecurity.com/)) for reporting this issue.",
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-13606\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-13606\nhttps://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/937cdd9920bd966517c5f7a3595397af96b6ab6f"
    ],
    "name": "CVE-2026-13606",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-24T00:00:00Z",
    "bugzilla": {
      "description": "libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack()",
      "id": "2493411",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493411"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-415",
    "details": [
      "A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.",
      "A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service."
    ],
    "statement": "Red Hat Product Security has assessed this CVE as 7.5 CVSS with Moderate security Impact. This assessment reflects the library's typical deployment within enterprise software, where libarchive is frequently embedded into automated, network-accessible services that receive and process archives originating from remote sources. In these environments, a specially crafted RAR5 archive may be delivered and processed automatically without requiring direct user interaction, allowing a remote attacker to trigger the vulnerability and cause the affected application or service processing the archive to terminate unexpectedly, resulting in a denial of service.\nFrom a standalone library perspective, however, the vulnerable code is only reached when an application opens and processes a crafted RAR5 archive. Evaluating libarchive in isolation, without considering downstream deployment models, the vulnerability more closely aligns with a CVSS score of 5.5-CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H (Moderate), reflecting an Attack Vector of Local (AV:L) and User Interaction Required (UI:R). This is because the crafted archive must first be delivered to and processed by a local application before the vulnerable parsing logic is executed. \nRed Hat's assigned score instead reflects the operational deployment of libarchive in automated, network-facing workloads in downstream environment models rather than the standalone library in isolation.\n```\nThis vulnerability only affects libarchive releases that include support for the RAR5 archive format. RAR5 support was first introduced upstream in libarchive 3.4.0 (https://github.com/libarchive/libarchive/wiki/ReleaseNotes#libarchive-340). Earlier libarchive releases do not contain the vulnerable RAR5 parsing code and are therefore not affected.\nRed Hat Enterprise Linux 6, 7, and 8 ship Libarchive versions prior to v3.4.0 that do not include RAR5 support and are therefore not affected.\n```",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52675",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libarchive-0:3.7.7-10.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56954",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libarchive-0:3.7.7-5.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52674",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libarchive-0:3.5.3-11.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52674",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libarchive-0:3.5.3-11.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58574",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libarchive-0:3.5.3-5.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58573",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "libarchive-0:3.5.3-5.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58558",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libarchive-0:3.5.3-7.el9_6.2"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54769",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202608130832-0"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54760",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1786638573"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-26T00:00:00Z",
        "advisory": "RHSA-2026:30333",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libarchive-main-3.8.8-2.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1786435241"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1786533457"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1786533449"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1786435483"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1786533529"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-14164\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-14164\nhttps://github.com/libarchive/libarchive/issues/3069\nhttps://github.com/libarchive/libarchive/pull/3071"
    ],
    "name": "CVE-2026-14164",
    "mitigation": {
      "value": "No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the appropriate security update once it becomes available.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-03T20:57:31Z",
    "bugzilla": {
      "description": "php: ext/openssl: memory corruption in openssl_encrypt with AES-WRAP-PAD",
      "id": "2496971",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496971"
    },
    "cvss3": {
      "cvss3_base_score": "5.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-122",
    "details": [
      "In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.",
      "A flaw was found in the OpenSSL extension of PHP. The AES-WRAP-PAD algorithm implementation uses the size of the plaintext length without accounting for the RFC 5649 expansion to allocate the output buffer for the AES key-wrap-with-padding operation. This may lead to an undersized memory allocation and subsequently a heap-based buffer overflow, causing memory corruption that later is surfaced as an application abort that results in a denial of service."
    ],
    "statement": "To exploit this issue, an attacker needs to find an application using the AES-WRAP-PAD algorithm. This algorithm is rarely used, limiting the exposure of this vulnerability. Additionally, the memory allocator can detect the heap-based buffer overflow and will abort the process with no other security impact. For these reasons, this issue has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:48170",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php-0:8.3.32-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49914",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php8.4-0:8.4.23-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-30T00:00:00Z",
        "advisory": "RHSA-2026:47749",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:8.2-8100020260710044340.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-30T00:00:00Z",
        "advisory": "RHSA-2026:47750",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:7.4-8100020260710051855.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40416",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.2-9080020260709074538.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48197",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.3-9080020260709051146.9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34164",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "php-main-8.5.8-2.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "php:8.4/php",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-14355\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-14355\nhttps://github.com/php/php-src/security/advisories/GHSA-7jrw-539f-x6vr"
    ],
    "name": "CVE-2026-14355",
    "mitigation": {
      "value": "To mitigate this vulnerability, do not use the AES-WRAP-PAD algorithm, by switching to a secure alternative.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-10T10:38:28Z",
    "bugzilla": {
      "description": "mtr: mtr: Denial of Service via crafted DNS responses",
      "id": "2498972",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498972"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-823",
    "details": [
      "mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT response used for AS lookups can trigger this bug by returning a DNS response that is larger than 512 bytes and uses a crafted compression pointer in the answer NAME field. ipinfo_lookup() function uses the length of the response as the end-of-message boundary for dn_expand() function. The result is a reliable crash.\nThis issue exists in the mtr through version 0.96 and it was fixed in commit 48e1794414d338ce47abc0f27c25ade8788af9c3.",
      "A flaw was found in mtr. A remote attacker, by influencing the DNS (Domain Name System) TXT response used for AS (Autonomous System) lookups, can trigger an out-of-bound read vulnerability in the `ipinfo_lookup()` function. This occurs when a DNS response larger than 512 bytes contains a crafted compression pointer in the answer NAME field. Successful exploitation leads to a reliable crash of the mtr application, resulting in a Denial of Service."
    ],
    "acknowledgement": "Red Hat would like to thank Michał Majchrowicz and Marcin Wyczechowski (AFINE Team) for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "mtr",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "mtr",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "mtr",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mtr",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mtr",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-14461\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-14461\nhttps://cert.pl/en/posts/2026/07/CVE-2026-14461\nhttps://github.com/traviscross/mtr/commit/48e1794414d338ce47abc0f27c25ade8788af9c3"
    ],
    "name": "CVE-2026-14461",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-07T09:00:00Z",
    "bugzilla": {
      "description": "sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation",
      "id": "2496556",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496556"
    },
    "cvss3": {
      "cvss3_base_score": "8.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1188",
    "details": [
      "A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.",
      "A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts."
    ],
    "statement": "Red Hat has rated this as Important because the attack requires only low-privilege delegated LDAP write access to any subtree, which is a common delegation pattern in enterprise environments. The default ldap_sudo_search_base configuration searches the entire directory tree, allowing sudo rule injection from outside the intended sudoers container.",
    "acknowledgement": "This issue was discovered by Ian Murphy (Red Hat).",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41937",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "sssd-0:2.12.0-3.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46482",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "sssd-0:2.10.2-3.el10_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50109",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "sssd-0:1.16.5-10.el7_9.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:46990",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "sssd-0:2.9.4-5.el8_10.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:46990",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "sssd-0:2.9.4-5.el8_10.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49841",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "sssd-0:2.4.0-9.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49841",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "sssd-0:2.4.0-9.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49844",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "sssd-0:2.6.2-4.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49844",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "sssd-0:2.6.2-4.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49842",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "sssd-0:2.8.2-4.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49842",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "sssd-0:2.8.2-4.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42122",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "sssd-0:2.9.8-4.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42122",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "sssd-0:2.9.8-4.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49843",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "sssd-0:2.8.2-5.el9_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49840",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "sssd-0:2.9.4-6.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49839",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "sssd-0:2.9.6-4.el9_6.5"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:54187",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202608111330-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:54553",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202608120446-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54581",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "rhcos-4.20.9.6.202608121719-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54599",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "rhcos-4.21.9.6.202608122143-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54769",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202608130832-0"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "sssd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-14474\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-14474"
    ],
    "name": "CVE-2026-14474",
    "mitigation": {
      "value": "Set ldap_sudo_search_base explicitly in /etc/sssd/sssd.conf to restrict the search to the designated sudoers container:\n[domain/example.com] ldap_sudo_search_base = ou=sudoers,dc=example,dc=com\nAdditionally, restrict LDAP ACLs to prevent non-admin principals from creating sudoRole objects outside the designated sudoers container.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-07T09:00:00Z",
    "bugzilla": {
      "description": "sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass",
      "id": "2496581",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496581"
    },
    "cvss3": {
      "cvss3_base_score": "8.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-23",
    "details": [
      "A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.",
      "A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass."
    ],
    "statement": "Red Hat has rated this as Moderate because exploitation requires high privileges (AD GPO management access) and on default RHEL configurations with SELinux enforcing, the realistic impact is limited to Kerberos authentication bypass via krb5 configuration injection. SELinux blocks writes to most security-critical paths such as /etc/cron.d/.",
    "acknowledgement": "This issue was discovered by Ian Murphy (Red Hat).",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41937",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "sssd-0:2.12.0-3.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46482",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "sssd-0:2.10.2-3.el10_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50109",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "sssd-0:1.16.5-10.el7_9.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:46990",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "sssd-0:2.9.4-5.el8_10.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:46990",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "sssd-0:2.9.4-5.el8_10.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49841",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "sssd-0:2.4.0-9.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49841",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "sssd-0:2.4.0-9.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49844",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "sssd-0:2.6.2-4.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49844",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "sssd-0:2.6.2-4.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49842",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "sssd-0:2.8.2-4.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49842",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "sssd-0:2.8.2-4.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42122",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "sssd-0:2.9.8-4.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42122",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "sssd-0:2.9.8-4.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49843",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "sssd-0:2.8.2-5.el9_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49840",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "sssd-0:2.9.4-6.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49839",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "sssd-0:2.9.6-4.el9_6.5"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:54187",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202608111330-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:54553",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202608120446-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54581",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "rhcos-4.20.9.6.202608121719-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54599",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "rhcos-4.21.9.6.202608122143-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54769",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202608130832-0"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "sssd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-14476\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-14476"
    ],
    "name": "CVE-2026-14476",
    "mitigation": {
      "value": "Set ad_gpo_access_control = disabled in /etc/sssd/sssd.conf to disable GPO fetching entirely. Note that this removes GPO-based login policy enforcement.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-07T22:05:18Z",
    "bugzilla": {
      "description": "DBI: DBI: Heap overflow when preparsing SQL statements with excessive placeholders",
      "id": "2497916",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497916"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders.\nThe fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders.\nDBI version 1.650 sets a hard limit of 99,999 placeholders.",
      "A flaw was found in DBI for Perl. This vulnerability, a heap overflow, occurs when the software attempts to preparse SQL statements containing an extremely large number of placeholders. This could allow a remote attacker to cause a denial of service or potentially execute arbitrary code."
    ],
    "statement": "This vulnerability in DBI for Perl is rated as Important. A heap overflow can occur when processing SQL statements with an exceptionally large number of placeholders, potentially leading to a denial of service or arbitrary code execution. While requiring an extreme number of placeholders, this flaw could impact applications utilizing DBI in Red Hat environments that handle untrusted or maliciously crafted SQL queries.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49514",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "perl-DBI-0:1.643-26.el10_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52772",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "perl-DBI:1.641-8100020260805130201.69ef70f8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49612",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "perl-DBI-0:1.643-9.el9_8.3"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-14739\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-14739\nhttps://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395.patch\nhttps://metacpan.org/release/HMBRAND/DBI-1.650/changes\nhttps://www.cve.org/CVERecord?id=CVE-2026-10879"
    ],
    "name": "CVE-2026-14739",
    "mitigation": {
      "value": "Applications utilizing `perl-DBI` should implement robust input validation and limit the number of parameters used in SQL query placeholders, particularly when processing untrusted data. This operational control can prevent the construction of SQL statements with an excessive number of placeholders, thereby reducing the risk of triggering the heap overflow vulnerability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder.\n\nThe pure-Perl decode path (`_decode_value` dispatching to `_decode_array` and `_decode_object`) recurses with no depth limit, so a small deeply nested JSON document can consume excessive memory.\n\nThis path is the default when Cpanel::JSON::XS is not installed or `MOJO_NO_JSON_XS=1` is set; the Cpanel::JSON::XS fast path is not affected.\n\nAny caller that decodes an untrusted JSON body, for example `Mojo::Message::json` reached through `$c->req->json`, can exhaust process memory and cause denial of service."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-14803\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-14803"
    ],
    "name": "CVE-2026-14803",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-15T00:00:00Z",
    "bugzilla": {
      "description": "libreswan: badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process",
      "id": "2501764",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501764"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-617",
    "details": [
      "A flaw was found in Libreswan. An unauthenticated remote attacker can send a specially crafted X.509 certificate payload during an IKEv1 or IKEv2 exchange. This flaw occurs when Libreswan is operating in FIPS (Federal Information Processing Standards) mode and processing a certificate with an invalid public key, such as an RSA exponent of zero. This can trigger an assertion failure, leading to the termination of the daemon process and a denial of service."
    ],
    "statement": "Moderate: This flaw in Libreswan, when operating in FIPS mode with certificate-based authentication, allows an unauthenticated remote attacker to trigger a denial of service. The assertion failure occurs during X.509 certificate processing with a malformed certificate, leading to the daemon crashing. \nThis impact is limited to specific configurations where both FIPS mode and certificate-based authentication are actively utilized. It means, when Libreswan is running in FIPS mode and certificate-based authentication is in use with at least one CA certificate loaded in the Libreswan NSS database. \nDeployments using only Pre-Shared Key (PSK) authentication without loaded CA certificates are not affected.",
    "affected_release": [
      {
        "product_name": "Fast Datapath for Red Hat Enterprise Linux 9",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46986",
        "cpe": "cpe:/o:redhat:enterprise_linux:9::fastdatapath",
        "package": "libreswan-0:5.3.2-1.el9fdp"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46398",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libreswan-0:5.3.2-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55449",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libreswan-0:5.2-1.el10_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46396",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libreswan-0:4.12-2.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46397",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libreswan-0:4.15-10.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57741",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libreswan-0:4.15-8.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libreswan",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "libreswan",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "libreswan",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-14957\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-14957\nhttps://libreswan.org/security/CVE-2026-14957/\nhttps://libreswan.org/security/CVE-2026-14957/CVE-2026-14957.txt"
    ],
    "name": "CVE-2026-14957",
    "mitigation": {
      "value": "No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the appropriate security updates once they become available.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-27T13:15:00Z",
    "bugzilla": {
      "description": "binutils: GNU Binutils: Heap-buffer-overflow in linker leads to information disclosure and denial of service",
      "id": "2497805",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497805"
    },
    "cvss3": {
      "cvss3_base_score": "5.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.",
      "A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."
    ],
    "statement": "This vulnerability is rated as High. A heap-buffer-overflow in the GNU Binutils linker (`ld`) can lead to information disclosure and denial of service when processing specially crafted 32-bit XCOFF object files. This occurs because the linker uses an unvalidated field from untrusted input as an array index, potentially exposing heap metadata or causing a crash during the linking process.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47171",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "binutils-main-2.46.1-1.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-15-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-16-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "mingw-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-14-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-14-gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-15-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-15-gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-14-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-15-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gcc-toolset-16-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gdb",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mingw-binutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-15003\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-15003\nhttps://sourceware.org/bugzilla/show_bug.cgi?id=34053"
    ],
    "name": "CVE-2026-15003",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-14T09:44:25Z",
    "bugzilla": {
      "description": "DBI::SQL::Nano: DBI::SQL::Nano: Incorrect SQL operator evaluation can lead to incorrect data filtering.",
      "id": "2499934",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499934"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-480",
    "details": [
      "DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text.\nDBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was evaluated using Perl's le operator.\nSQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.\nThe impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted <=/>= comparison silently returns the wrong rows.",
      "A flaw was found in DBI::SQL::Nano, a mini-SQL engine for Perl. This vulnerability occurs because the engine incorrectly evaluates SQL operators for text comparisons, specifically inverting the logic for \"less than or equal to\" and \"greater than or equal to\" operations. This can lead to applications that rely on these comparisons for filtering data, such as for policy or authorization, silently returning incorrect results. The impact of this flaw depends on how an application uses these SQL queries."
    ],
    "statement": "A Moderate impact flaw in perl-DBI's SQL::Nano engine can lead to incorrect data filtering. This issue arises when applications use file-backed drivers with SQL::Nano as the fallback SQL engine, causing text comparison operators (`<=` and `>=`) to be inverted. This could result in applications silently returning incorrect data, potentially affecting policy enforcement or authorization decisions.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "perl-DBI:1.641/perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-15043\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-15043\nhttps://github.com/perl5-dbi/dbi/commit/e9742ef85a75867cbd696860e3bf3e32b681f98d.patch\nhttps://github.com/perl5-dbi/dbi/security/advisories/GHSA-mv45-ff6j-x9jp"
    ],
    "name": "CVE-2026-15043",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-10T18:20:58Z",
    "bugzilla": {
      "description": "wget: Wget: Server-Side Request Forgery via FTP PASV response IP address validation bypass",
      "id": "2499143",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499143"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "draft"
    },
    "cwe": "CWE-918",
    "details": [
      "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
      "A flaw was found in Wget. When operating in FTP passive mode, Wget fails to validate the IP address provided in an FTP PASV response. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this vulnerability to redirect Wget's data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially leading to unauthorized access to localhost services or internal network resources."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-15146\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-15146\nhttps://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b\nhttps://kb.cert.org/vuls/id/564823"
    ],
    "name": "CVE-2026-15146",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-26T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-15534\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-15534"
    ],
    "name": "CVE-2026-15534",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-14T00:00:00Z",
    "bugzilla": {
      "description": "samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validation",
      "id": "2499991",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499991"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-732",
    "details": [
      "A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.",
      "A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation."
    ],
    "statement": "Red Hat Product Security rates this flaw's impact as Moderate. Exploitation requires mkhomedir to be explicitly enabled in pam_winbind.conf, a non-default option used specifically in Active Directory domain-integration deployments, and a PAM session to be opened for an account whose home directory resolves to /. While the most direct trigger is root running su to such an account, a non-root user holding a narrow sudo delegation to run a command as that account can reach the same code path. The resulting impact is denial of service through broken ownership checks affecting SSH, sudo, and package management, not privilege escalation: Red Hat Enterprise Linux ships / with restrictive 0555 permissions, so the new unprivileged owner is not granted write access to the filesystem root. Red Hat Enterprise Linux 9.9 and 10.3 are not affected, as an unrelated upstream refactor changed the home-directory-creation logic so ownership is only changed when a new directory is actually created rather than when the target already exists.",
    "acknowledgement": "This issue was discovered by Runar Lundgren (Red Hat).",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "samba-winbind",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "samba-winbind",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Will not fix",
        "package_name": "samba-winbind",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "samba-winbind",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "samba-winbind",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-15779\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-15779\nhttps://gitlab.com/samba-team/samba/-/blob/samba-4.19.4/nsswitch/pam_winbind.c\nhttps://gitlab.com/samba-team/samba/-/blob/samba-4.23.5/nsswitch/pam_winbind.c#L1622\nhttps://gitlab.com/samba-team/samba/-/blob/samba-4.24.3/nsswitch/pam_winbind.c#L1590"
    ],
    "name": "CVE-2026-15779",
    "mitigation": {
      "value": "Do not enable mkhomedir in pam_winbind.conf on systems where any account (including system accounts) may resolve to a home directory of / or another sensitive system path.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-27T02:23:23Z",
    "bugzilla": {
      "description": "xmlrpc-c: XMLRPC-C Library: Cross-Site Scripting in error page component",
      "id": "2507394",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507394"
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-79",
    "details": [
      "XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.",
      "A flaw was found in the XMLRPC-C Library. This reflected cross-site scripting (XSS) vulnerability exists in the error page component. A remote attacker could exploit this by tricking a user into clicking a specially crafted link. Successful exploitation could lead to the execution of malicious scripts in the user's browser, potentially resulting in information disclosure or session hijacking."
    ],
    "statement": "This reflected cross-site scripting (XSS) vulnerability relies entirely on client-side interaction through a web browser. Practical exploitation requires a remote attacker to trick a user into clicking a targeted link that passes crafted input to an application displaying the XMLRPC-C error page. If executed, the script runs within the context of the user's browser session, making sensitive session tokens or client-side data accessible to the attacker.\nWhile external CVSSv4 scoring rates this flaw to an 8.2 High, Red Hat bounds the severity to CVSS 7.4 based on explicit CIA triad mechanics. The impact is strictly confined to Confidentiality (C:H) via potential browser-side data disclosure. The flaw carries zero impact on system Integrity (I:N) or Availability (A:N), as it cannot alter server-side application logic, modify stored data, or disrupt underlying XML-RPC services.\nDeployments operating strictly as headless backend services, non-interactive daemons, or server-to-server API endpoints—where the XMLRPC-C error component is never exposed or rendered inside a user's web browser—are fundamentally outside the execution boundary of this flaw and remain at zero risk.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xmlrpc-c",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "xmlrpc-c",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "xmlrpc-c",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "xmlrpc-c",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "important"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-15928\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-15928\nhttps://www.themissinglink.com.au/security-advisories/cve-2026-15928\nhttps://xmlrpc-c.sourceforge.io/"
    ],
    "name": "CVE-2026-15928",
    "mitigation": {
      "value": "To mitigate this issue, ensure that applications utilizing the XMLRPC-C library do not directly expose its error pages to end-users via a web browser. Configure web servers or application frontends to intercept and sanitize or replace error responses originating from XMLRPC-C before they are rendered client-side. Alternatively, restrict XMLRPC-C deployments to backend services that do not present error output in a user-facing web interface.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-04T15:02:06Z",
    "bugzilla": {
      "description": "nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections",
      "id": "2436738",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436738"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-349",
    "details": [
      "A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in NGINX. When NGINX is configured to proxy to upstream Transport Layer Security (TLS) servers, An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4705",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nginx-2:1.26.3-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6311",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "nginx-2:1.26.3-1.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5581",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nginx:1.24-8100020260223105706.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-03T00:00:00Z",
        "advisory": "RHSA-2026:3638",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.24-9070020260219154412.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4235",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.26-9070020260219144748.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5599",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx-2:1.20.1-24.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6408",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "nginx-1:1.20.1-10.el9_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6235",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "nginx-1:1.20.1-14.el9_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6234",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nginx-1:1.20.1-16.el9_4.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6407",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nginx:1.24-9040020260331102155.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6182",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx-2:1.20.1-22.el9_6.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6302",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx:1.24-9060020260327134414.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6427",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx:1.26-9060020260331094920.9"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4501",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1773273070"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8346",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nginx-main-1.30.0-1.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1773670073"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Lightspeed proxy 1",
        "fix_state": "Affected",
        "package_name": "insights-proxy/insights-proxy-container-rhel9",
        "cpe": "cpe:/a:redhat:insights_proxy:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-1642\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-1642\nhttps://my.f5.com/manage/s/article/K000159824"
    ],
    "name": "CVE-2026-1642",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-07-03T00:00:00Z",
    "bugzilla": {
      "description": "libarchive: libarchive: Signed Integer Overflow in archive_write_zip_header",
      "id": "2505492",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2505492"
    },
    "cvss3": {
      "cvss3_base_score": "2.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.",
      "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption."
    ],
    "statement": "Red Hat Product Security rates this issue as Low severity. The vulnerability is in the ZIP write path only and requires both ZIP encryption to be enabled and a file size near INT64_MAX, making real-world exploitation highly unlikely. The resulting undefined behavior could theoretically cause incorrect Zip64 extension decisions or a crash, but the conditions are too contrived for practical exploitation.",
    "acknowledgement": "Red Hat would like to thank shaohan.X for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43818",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libarchive-main-3.8.8-3.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-16517\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-16517"
    ],
    "name": "CVE-2026-16517",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-30T11:22:04Z",
    "bugzilla": {
      "description": "php: ext-pgsql: PHP: SQL injection via improper backslash escaping",
      "id": "2509254",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509254"
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-89",
    "details": [
      "Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.",
      "A flaw was found in PHP. Improper escaping of backslashes in attacker-provided parameters can lead to a SQL injection vulnerability. A remote attacker could exploit this flaw by crafting malicious input, potentially gaining unauthorized access to sensitive information, manipulating data, or causing a denial of service."
    ],
    "statement": "The Red Hat Product Security team has assessed the severity of this vulnerability as Important. A remote attacker could exploit this flaw to inject malicious SQL commands into a connected PostgreSQL database, potentially exposing or manipulating sensitive data. However, only applications using PHP's older pg_insert(), pg_update(), pg_select(), or pg_delete() functions with unsanitized user input are at risk  applications built on modern practices such as PDO, prepared statements, or parameterized queries are not affected. The vulnerability stems from improper handling of backslash characters in PHP's PostgreSQL extension, which can allow an attacker to break out of expected query boundaries and execute unintended SQL commands.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56969",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php8.4-0:8.4.24-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57574",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:8.2-8100020260806050858.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57539",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.3-9080020260806131732.9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47200",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "php-main-8.5.9-1.hum1",
        "impact": "critical"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "php:7.4/php",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "php:8.2/php",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-17543\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-17543\nhttps://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4"
    ],
    "name": "CVE-2026-17543",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-02T00:00:00Z",
    "bugzilla": {
      "description": "libsoup: SoupServer: Denial of Service via HTTP request smuggling",
      "id": "2435951",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2435951"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-444",
    "details": [
      "A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated client can exploit this by sending specially crafted requests, causing SoupServer to fail to close the connection as required by RFC 9112. This allows the attacker to smuggle additional requests over the persistent connection, leading to unintended request processing and potential denial-of-service (DoS) conditions.",
      "A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated client can exploit this by sending specially crafted requests, causing SoupServer to fail to close the connection as required by RFC 9112. This allows the attacker to smuggle additional requests over the persistent connection, leading to unintended request processing and potential denial-of-service (DoS) conditions."
    ],
    "statement": "A moderate-impact HTTP request smuggling vulnerability exists in SoupServer due to improper connection handling. When processing requests that use Transfer-Encoding: chunked together with Connection: keep-alive, the server fails to close the connection as required by the HTTP specification. This may allow additional client-supplied data to be interpreted as a new HTTP request, leading to unintended request processing or denial-of-service conditions. SoupServer is primarily intended for lightweight, internal, development, or testing use cases rather than hardened internet-facing deployments, which limits the practical impact of this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libsoup3",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-1760\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-1760\nhttps://gitlab.gnome.org/GNOME/libsoup/-/issues/475"
    ],
    "name": "CVE-2026-1760",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-02-03T00:00:00Z",
    "bugzilla": {
      "description": "libsoup: libsoup: HTTP Request Smuggling via malformed chunk headers",
      "id": "2436315",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436315"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-444",
    "details": [
      "A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return and line feed (CRLF). A remote attacker can exploit this without authentication or user interaction by sending specially crafted chunked requests. This allows libsoup to parse and process multiple HTTP requests from a single network message, potentially leading to information disclosure.",
      "A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return and line feed (CRLF). A remote attacker can exploit this without authentication or user interaction by sending specially crafted chunked requests. This allows libsoup to parse and process multiple HTTP requests from a single network message, potentially leading to information disclosure."
    ],
    "statement": "This issue has a LOW impact. The libsoup library is vulnerable to HTTP Request Smuggling due to non-RFC-compliant parsing of chunk headers. While exploitation is possible remotely without authentication, the impact on Red Hat products is limited as the SoupServer component, which is affected by this flaw, is not commonly deployed in internet-facing infrastructure.",
    "acknowledgement": "Red Hat would like to thank Ahmed Lekssays for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libsoup3",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-1801\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-1801\nhttps://gitlab.gnome.org/GNOME/libsoup/-/issues/481"
    ],
    "name": "CVE-2026-1801",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-20T16:22:54Z",
    "bugzilla": {
      "description": "gimp: gegl: GIMP: Remote code execution via integer overflow in HDR file parsing",
      "id": "2520587",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520587"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\nThe specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29289.",
      "A flaw was found in GIMP, specifically within the parsing of High Dynamic Range (HDR) files. This integer overflow vulnerability occurs due to insufficient validation of user-supplied data before memory allocation. A remote attacker could exploit this by convincing a user to open a specially crafted malicious HDR file, leading to arbitrary code execution in the context of the current process."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-09-02T00:00:00Z",
        "advisory": "RHSA-2026:62420",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gegl04-0:0.4.4-7.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-09-02T00:00:00Z",
        "advisory": "RHSA-2026:62425",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gegl-0:0.2.0-40.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-09-01T00:00:00Z",
        "advisory": "RHSA-2026:62170",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gegl04-0:0.4.62-1.el9_8.2"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "gegl04",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gegl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "gegl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "gimp:2.8/gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-18300\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-18300\nhttps://gitlab.gnome.org/GNOME/gegl/-/commit/d3d262008299341c5b032b354021632ceadb2799\nhttps://www.zerodayinitiative.com/advisories/ZDI-26-453/"
    ],
    "name": "CVE-2026-18300",
    "mitigation": {
      "value": "Users should exercise caution when opening HDR files from untrusted sources. It is recommended to only open HDR files from known and trusted origins to reduce the risk of exploitation. Additionally, consider running GIMP within a sandboxed environment if processing untrusted files is a regular activity.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-25T00:00:00Z",
    "bugzilla": {
      "description": "gstreamer: incomplete fix of CVE-2026-1940",
      "id": "2436932",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436932"
    },
    "cvss3": {
      "cvss3_base_score": "5.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "status": "draft"
    },
    "details": [
      "An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.",
      "An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read."
    ],
    "acknowledgement": "Red Hat would like to thank wooseokdotkim for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gstreamer1",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gstreamer",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "gstreamer",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "gstreamer1",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gstreamer1",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-gstreamer1",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gstreamer1",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-1940\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-1940\nhttps://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/4854\nhttps://gstreamer.freedesktop.org/security/sa-2026-0001.html\nhttps://security-tracker.debian.org/tracker/CVE-2026-1940"
    ],
    "name": "CVE-2026-1940",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-11T10:08:52Z",
    "bugzilla": {
      "description": "curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication",
      "id": "2446448",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
    },
    "cvss3": {
      "cvss3_base_score": "6.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-303",
    "details": [
      "libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).",
      "A flaw was found in curl. When an application uses libcurl to make multiple Negotiate-authenticated HTTP or HTTPS requests to the same server with different credentials, libcurl may incorrectly reuse an existing connection. This logical error can cause a subsequent request to be sent using the authentication of a previous user, leading to an authentication bypass."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55450",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "curl-0:8.12.1-4.el10_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55439",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "curl-0:7.76.1-40.el9_8.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55439",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "curl-0:7.76.1-40.el9_8.5"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6893",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.19.0-3.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/recert-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Fix deferred",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-1965\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-1965\nhttps://curl.se/docs/CVE-2026-1965.html\nhttps://curl.se/docs/CVE-2026-1965.json"
    ],
    "name": "CVE-2026-1965",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-02-20T22:23:23Z",
    "bugzilla": {
      "description": "gimp: GIMP: Remote Code Execution via uninitialized memory in PGM file parsing",
      "id": "2441521",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2441521"
    },
    "cvss3": {
      "cvss3_base_score": "8.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-908",
    "details": [
      "GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\nThe specific flaw exists within the parsing of PGM files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28158.",
      "A flaw was found in GIMP. This uninitialized memory vulnerability allows a remote attacker to execute arbitrary code on affected installations. Successful exploitation requires user interaction, where the target must open a specially crafted PGM (Portable Graymap) image file. This can lead to arbitrary code execution in the context of the current process."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5113",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gimp:2.8-8100020260312152017.4c9c024f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5435",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "gimp:2.8-8020020260319131243.c3a0935b"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5436",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gimp:2.8-8040020260320114321.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5436",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gimp:2.8-8040020260320114321.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5434",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gimp:2.8-8060020260319125557.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5434",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gimp:2.8-8060020260319125557.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5434",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gimp:2.8-8060020260319125557.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5437",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gimp:2.8-8080020260319123205.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5437",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gimp:2.8-8080020260319123205.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4173",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-1.el9_7.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5390",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gimp-2:2.99.8-3.el9_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5389",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gimp-2:2.99.8-4.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5391",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gimp-2:2.99.8-4.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5388",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gimp-2:2.99.8-4.el9_6.6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2044\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2044\nhttps://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2569/diffs?commit_id=112a5e038f0646eae5ae314988ec074433d2b365\nhttps://www.zerodayinitiative.com/advisories/ZDI-26-118/"
    ],
    "name": "CVE-2026-2044",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-02-20T22:23:32Z",
    "bugzilla": {
      "description": "gimp: GIMP: Remote Code Execution via out-of-bounds write in XWD file parsing",
      "id": "2441522",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2441522"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\nThe specific flaw exists within the parsing of XWD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28265.",
      "A flaw was found in GIMP. The specific flaw exists within the parsing of XWD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5113",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gimp:2.8-8100020260312152017.4c9c024f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5435",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "gimp:2.8-8020020260319131243.c3a0935b"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5436",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gimp:2.8-8040020260320114321.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5436",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gimp:2.8-8040020260320114321.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5434",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gimp:2.8-8060020260319125557.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5434",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gimp:2.8-8060020260319125557.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5434",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gimp:2.8-8060020260319125557.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5437",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gimp:2.8-8080020260319123205.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5437",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gimp:2.8-8080020260319123205.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4173",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-1.el9_7.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5390",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gimp-2:2.99.8-3.el9_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5389",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gimp-2:2.99.8-4.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5391",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gimp-2:2.99.8-4.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5388",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gimp-2:2.99.8-4.el9_6.6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2045\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2045\nhttps://gitlab.gnome.org/GNOME/gimp/-/commit/68b27dfb1cbd9b3f22d7fa624dbab8647ee5f275\nhttps://www.zerodayinitiative.com/advisories/ZDI-26-119/"
    ],
    "name": "CVE-2026-2045",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-02-20T22:23:51Z",
    "bugzilla": {
      "description": "gimp: GIMP: Remote Code Execution via XWD file parsing vulnerability",
      "id": "2441527",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2441527"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\nThe specific flaw exists within the parsing of XWD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28591.",
      "A flaw was found in GIMP. A remote attacker can exploit this out-of-bounds write vulnerability by tricking a user into opening a specially crafted XWD (X Window Dump) file. This issue occurs due to improper validation of user-supplied data during XWD file parsing, leading to a write past the end of an allocated buffer. Successful exploitation could allow the attacker to execute arbitrary code in the context of the current process."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5113",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gimp:2.8-8100020260312152017.4c9c024f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5435",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "gimp:2.8-8020020260319131243.c3a0935b"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5436",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gimp:2.8-8040020260320114321.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5436",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gimp:2.8-8040020260320114321.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5434",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gimp:2.8-8060020260319125557.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5434",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gimp:2.8-8060020260319125557.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5434",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gimp:2.8-8060020260319125557.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5437",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gimp:2.8-8080020260319123205.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5437",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gimp:2.8-8080020260319123205.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4173",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-1.el9_7.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5390",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gimp-2:2.99.8-3.el9_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5389",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gimp-2:2.99.8-4.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5391",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gimp-2:2.99.8-4.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5388",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gimp-2:2.99.8-4.el9_6.6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2048\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2048\nhttps://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2586/diffs?commit_id=57712677007793118388c5be6fb8231f22a2b341\nhttps://www.zerodayinitiative.com/advisories/ZDI-26-121/"
    ],
    "name": "CVE-2026-2048",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-10T21:22:47Z",
    "bugzilla": {
      "description": "gimp: gegl: GIMP: Remote Code Execution via HDR File Parsing Heap-based Buffer Overflow",
      "id": "2487738",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487738"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-131",
    "details": [
      "GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\nThe specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28618.",
      "A flaw was found in GIMP. This heap-based buffer overflow vulnerability, located in the HDR file parsing component, allows a remote attacker to execute arbitrary code. User interaction is required for exploitation, as the target must open a malicious HDR file. The flaw occurs due to a lack of proper validation of user-supplied data length before it is copied to a heap-based buffer."
    ],
    "statement": "This is an Important vulnerability in GIMP, as a heap-based buffer overflow in the HDR file parsing component can lead to remote code execution. While exploitation requires user interaction, specifically opening a malicious HDR file, successful attacks could allow an attacker to execute arbitrary code within the context of the affected user. This risk is primarily present on desktop systems where GIMP is installed and used to process untrusted image files.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2049\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2049\nhttps://gitlab.gnome.org/GNOME/gegl/-/issues/450\nhttps://www.zerodayinitiative.com/advisories/ZDI-26-214/"
    ],
    "name": "CVE-2026-2049",
    "mitigation": {
      "value": "To mitigate this issue, users should avoid opening HDR files from untrusted or suspicious sources. If GIMP is not required, consider removing the `gimp` package to eliminate the attack surface. This can be achieved with `sudo dnf remove gimp`. Be aware that removing GIMP may impact other dependent graphical applications.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-24T21:43:46Z",
    "bugzilla": {
      "description": "gimp: GIMP: Arbitrary code execution via heap-based buffer overflow in HDR file parsing",
      "id": "2492593",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492593"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\nThe specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28266.",
      "A flaw was found in GIMP. This vulnerability, a heap-based buffer overflow, occurs during the parsing of HDR (High Dynamic Range) files due to insufficient validation of user-supplied data length. A remote attacker could exploit this by convincing a user to open a specially crafted malicious file, leading to arbitrary code execution within the context of the current process."
    ],
    "statement": "This Important vulnerability in GIMP allows for arbitrary code execution through a heap-based buffer overflow during HDR file parsing. Successful exploitation requires user interaction, where an attacker must persuade a user to open a malicious file. This prerequisite reduces the immediate threat compared to remote, unauthenticated flaws, but the potential for system compromise warrants an Important rating.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38485",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gegl-0:0.2.0-40.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38497",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gegl04-0:0.4.62-1.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56982",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gegl04-0:0.4.34-2.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56964",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gegl04-0:0.4.34-3.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56963",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gegl04-0:0.4.34-3.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2050\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2050\nhttps://gitlab.gnome.org/GNOME/gegl/-/merge_requests/241\nhttps://www.zerodayinitiative.com/advisories/ZDI-26-282/"
    ],
    "name": "CVE-2026-2050",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-07T13:49:22Z",
    "bugzilla": {
      "description": "LibRaw: LibRaw: Arbitrary code execution via integer overflow in deflate_dng_load_raw",
      "id": "2455934",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455934"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.",
      "A flaw was found in LibRaw. An integer overflow vulnerability in the `deflate_dng_load_raw` functionality allows a remote attacker to provide a specially crafted malicious file. This can lead to a heap buffer overflow, potentially resulting in arbitrary code execution."
    ],
    "statement": "This flaw in the LibRaw library consists in an integer overflow in the `deflate_dng_load_raw()` function, a successfully performed attack may lead to a heap buffer overflow and potentially arbitrary code execution or denial of service. The vulnerability stems from the usage of a 32-bit arithmetic to calculate the memory limits and the buffer allocation size for the image's tile dimension values, which may end up overflowing when processing user controlled images as input. The calculation result is further used within 64-bit boundary checking however the proper cast is missing and the result value is used to allocate the buffer from memory, when the overflow happens the function may start writing outside of the expected memory boundary leading to data corruption.\nThis vulnerability is not exploitable when the application consuming LibRaw is using the default memory limit (`max_raw_memory_mb` parameter) to unpack the RAW image. To be considered vulnerable the application should be setting the limit to around or greater then 11GB.\nRed Hat Product Security has rated this vulnerability as having a Moderate impact, despite the possibility of arbitrary code execution due to the heap-based buffer overflow, as the user needs to be tricked to process a maliciously crafted image or LibRaw needs to be exposed to the network and accepting untrusted data as input. Additionally the default `max_raw_memory_mb` value set with LibRaw is not enough to trigger the vulnerability.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-20884\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-20884\nhttps://github.com/LibRaw/LibRaw/releases/tag/0.22.1\nhttps://talosintelligence.com/vulnerability_reports/TALOS-2026-2364"
    ],
    "name": "CVE-2026-20884",
    "mitigation": {
      "value": "This vulnerability can be mitigated by limiting the amount of memory used to unpack untrusted RAW images. This needs to be set in the application using the LibRaw and can be achieved by setting the `max_raw_memory_mb` to a value smaller than 16GB.\nThis parameter can't be changed in runtime in the library, so developers needs to patch and rebuild their application to impose the new limit. It's important to notice the fact when reducing the memory limit for the decoding process may render the library unable to handle big images.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-07T13:49:27Z",
    "bugzilla": {
      "description": "LibRaw: LibRaw: Arbitrary code execution via specially crafted image file",
      "id": "2455942",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455942"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.",
      "A flaw was found in LibRaw, a library used for processing raw image files. This vulnerability, a heap-based buffer overflow, exists within the x3f_thumb_loader functionality. A remote attacker could exploit this by tricking a user into opening a specially crafted malicious file. Successful exploitation could lead to arbitrary code execution, giving the attacker full control over the affected system."
    ],
    "statement": "LibRaw is not installed by default on Red Hat systems. A user would need to manually install and make available an affected code path for this vulnerability to be exploitable.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13284",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "LibRaw-0:0.19.5-6.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14224",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "LibRaw-0:0.19.5-2.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14224",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "LibRaw-0:0.19.5-2.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14655",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "LibRaw-0:0.19.5-3.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14655",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "LibRaw-0:0.19.5-3.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14655",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "LibRaw-0:0.19.5-3.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14673",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "LibRaw-0:0.19.5-3.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14673",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "LibRaw-0:0.19.5-3.el8_8.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-20889\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-20889\nhttps://talosintelligence.com/vulnerability_reports/TALOS-2026-2358"
    ],
    "name": "CVE-2026-20889",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-07T13:49:31Z",
    "bugzilla": {
      "description": "LibRaw: LibRaw: Arbitrary Code Execution via specially crafted file",
      "id": "2455959",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455959"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-120",
    "details": [
      "A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.",
      "A flaw was found in LibRaw. A remote attacker can exploit a heap-based buffer overflow vulnerability in the HuffTable::initval functionality by providing a specially crafted malicious file. This can lead to arbitrary code execution or a denial of service (DoS) on the affected system."
    ],
    "statement": "LibRaw is not installed by default on Red Hat systems. A user would need to manually install and make available an affected code path for this vulnerability to be exploitable.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Will not fix",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-20911\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-20911\nhttps://talosintelligence.com/vulnerability_reports/TALOS-2026-2330"
    ],
    "name": "CVE-2026-20911",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-07T13:49:29Z",
    "bugzilla": {
      "description": "LibRaw: LibRaw: Arbitrary code execution via heap-based buffer overflow in lossless JPEG loading",
      "id": "2455929",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455929"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.",
      "A flaw was found in LibRaw. A heap-based buffer overflow vulnerability exists in the `lossless_jpeg_load_raw` functionality. A remote attacker can exploit this by providing a specially crafted malicious file. This can lead to arbitrary code execution, allowing the attacker to take control of the affected system, or cause a denial of service (DoS)."
    ],
    "statement": "LibRaw is not installed by default on Red Hat systems. A user would need to manually install and make available an affected code path for this vulnerability to be exploitable.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13284",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "LibRaw-0:0.19.5-6.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14224",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "LibRaw-0:0.19.5-2.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14224",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "LibRaw-0:0.19.5-2.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14655",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "LibRaw-0:0.19.5-3.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14655",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "LibRaw-0:0.19.5-3.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14655",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "LibRaw-0:0.19.5-3.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14673",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "LibRaw-0:0.19.5-3.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14673",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "LibRaw-0:0.19.5-3.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11360",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "LibRaw-0:0.21.1-2.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19345",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "LibRaw-0:0.21.1-2.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13860",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "LibRaw-0:0.20.2-6.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13868",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "LibRaw-0:0.20.2-6.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13870",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "LibRaw-0:0.21.1-2.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13854",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "LibRaw-0:0.21.1-2.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Will not fix",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-21413\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-21413\nhttps://talosintelligence.com/vulnerability_reports/TALOS-2026-2331"
    ],
    "name": "CVE-2026-21413",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-20T20:41:55Z",
    "bugzilla": {
      "description": "nodejs: Nodejs denial of service",
      "id": "2431340",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431340"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-248",
    "details": [
      "A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.",
      "A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped."
    ],
    "statement": "Systems configured according to Red Hat guidelines should have their services set to restart in the event of a process crash. This Host system service management mitigates the availability impact to Red Hat customers.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1842",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nodejs24-1:24.13.0-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-05T00:00:00Z",
        "advisory": "RHSA-2026:1843",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nodejs22-1:22.22.0-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7675",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nodejs24-1:24.14.1-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2899",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "nodejs22-1:22.22.0-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2420",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nodejs:24-8100020260116121421.6d880403"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2421",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nodejs:22-8100020260119091831.6d880403"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2422",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nodejs:20-8100020260119100525.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7670",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nodejs:24-8100020260408131901.6d880403"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2781",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nodejs:24-9070020260117213814.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2782",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nodejs:22-9070020260117213838.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2783",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nodejs:20-9070020260117213748.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7350",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nodejs:24-9070020260402152654.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2768",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nodejs:20-9040020260211171433.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-17T00:00:00Z",
        "advisory": "RHSA-2026:2767",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nodejs:20-9060020260210180816.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2864",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nodejs:22-9060020260210120402.rhel9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6402",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nodejs24-main-24.14.1-4.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6431",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nodejs25-main-25.9.0-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7386",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nodejs20-main-20.20.0-7.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7387",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nodejs22-main-22.22.0-1.3.hum1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-21637\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-21637\nhttps://nodejs.org/en/blog/vulnerability/december-2025-security-releases"
    ],
    "name": "CVE-2026-21637",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-30T19:07:28Z",
    "bugzilla": {
      "description": "Node.js: Node.js: Memory leak and Denial of Service via crafted HTTP/2 WINDOW_UPDATE frames",
      "id": "2453161",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453161"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-772",
    "details": [
      "A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up.\nThis vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.",
      "A flaw was found in Node.js. A remote attacker can exploit this vulnerability in Node.js HTTP/2 servers by sending specially crafted WINDOW_UPDATE frames on stream 0 (connection-level). These frames can cause the flow control window to exceed its maximum value, leading to a memory leak as Http2Session objects are not properly cleaned up. This can result in resource exhaustion and a Denial of Service (DoS) condition for the server."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7675",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nodejs24-1:24.14.1-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7670",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nodejs:24-8100020260408131901.6d880403"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7350",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nodejs:24-9070020260402152654.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "nodejs22",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:20/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:22/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:20/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:22/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-21714\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-21714\nhttps://nodejs.org/en/blog/vulnerability/march-2026-security-releases"
    ],
    "name": "CVE-2026-21714",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-20T00:00:00Z",
    "bugzilla": {
      "description": "mysql: InnoDB unspecified vulnerability (CPU Jan 2026)",
      "id": "2431402",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431402"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4162",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.8-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5580",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260223150324.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6391",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260219114250.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4828",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.45-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5640",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020260313201256.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-21936\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-21936\nhttps://www.oracle.com/security-alerts/cpujan2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-21936",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-20T00:00:00Z",
    "bugzilla": {
      "description": "mysql: DDL unspecified vulnerability (CPU Jan 2026)",
      "id": "2431413",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431413"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4162",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.8-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5580",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260223150324.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6391",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260219114250.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4828",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.45-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5640",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020260313201256.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-21937\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-21937\nhttps://www.oracle.com/security-alerts/cpujan2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-21937",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-20T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Jan 2026)",
      "id": "2431384",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431384"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4162",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.8-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5580",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260223150324.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6391",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260219114250.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4828",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.45-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5640",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020260313201256.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-21941\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-21941\nhttps://www.oracle.com/security-alerts/cpujan2026.html\nhttps://www.oracle.com/security-alerts/cpujan2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-21941",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-20T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Jan 2026)",
      "id": "2431385",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431385"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4162",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.8-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5580",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260223150324.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6391",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260219114250.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4828",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.45-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5640",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020260313201256.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-21948\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-21948\nhttps://www.oracle.com/security-alerts/cpujan2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-21948",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-20T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Thread Pooling unspecified vulnerability (CPU Jan 2026)",
      "id": "2431431",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431431"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4162",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.8-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5580",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260223150324.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6391",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260219114250.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4828",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.45-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5640",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020260313201256.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-21964\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-21964\nhttps://www.oracle.com/security-alerts/cpujan2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-21964",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-20T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Jan 2026)",
      "id": "2431409",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431409"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4162",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "mysql8.4-0:8.4.8-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0376",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "mariadb10.11-3:10.11.15-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5580",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260223150324.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6391",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260219114250.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6435",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mariadb:10.11-8100020260219154532.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4828",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.45-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5640",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9070020260313201256.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0335",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "mariadb:10.11-9040020251210090406.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-01-08T00:00:00Z",
        "advisory": "RHSA-2026:0334",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "mariadb:10.11-9060020251210150813.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "mariadb10.11",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "mariadb:10.11/mariadb",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-21968\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-21968\nhttps://www.oracle.com/security-alerts/cpujan2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-21968",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Apr 2026)",
      "id": "2460312",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460312"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-21998\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-21998\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-21998",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Information Schema unspecified vulnerability (CPU Apr 2026)",
      "id": "2460275",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460275"
    },
    "cvss3": {
      "cvss3_base_score": "2.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-538",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-22001\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-22001\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-22001",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Apr 2026)",
      "id": "2460324",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460324"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-22002\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-22002\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-22002",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: InnoDB unspecified vulnerability (CPU Apr 2026)",
      "id": "2460274",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460274"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-22004\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-22004\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-22004",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Apr 2026)",
      "id": "2460315",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460315"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-22005\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-22005\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-22005",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Apr 2026)",
      "id": "2460279",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460279"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-22009\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-22009\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-22009",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Information Schema unspecified vulnerability (CPU Apr 2026)",
      "id": "2460348",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460348"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-201",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-22015\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-22015\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-22015",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Apr 2026)",
      "id": "2460342",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460342"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-22017\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-22017\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-22017",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-02-09T07:07:00Z",
    "bugzilla": {
      "description": "gimp: GIMP: Application crash (DoS) via crafted PSD file due to heap-buffer-overflow",
      "id": "2437675",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2437675"
    },
    "cvss3": {
      "cvss3_base_score": "2.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-170",
    "details": [
      "A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly null-terminated, leading to an out-of-bounds read when strlen() is subsequently called. Successfully exploiting this vulnerability can cause the application to crash, resulting in an application level Denial of Service.",
      "A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly null-terminated, leading to an out-of-bounds read when strlen() is subsequently called. Successfully exploiting this vulnerability can cause the application to crash, resulting in an application level Denial of Service."
    ],
    "statement": "This LOW impact flaw in GIMP can lead to an application level denial of service when processing a specially crafted PSD file. The vulnerability occurs due to a heap-buffer-overflow when reading Pascal strings, causing the application to crash. Exploitation requires user interaction to open a malicious PSD file.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gimp:2.8/gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2239\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2239\nhttps://gitlab.gnome.org/GNOME/gimp/-/issues/15812"
    ],
    "name": "CVE-2026-2239",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-10T09:09:00Z",
    "bugzilla": {
      "description": "gimp: GIMP: Denial of service via crafted PSP image file",
      "id": "2438429",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2438429"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file is used for memory allocation without proper validation, leading to a heap overflow and an out-of-bounds write. Successful exploitation could result in an application level denial of service.",
      "A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file is used for memory allocation without proper validation, leading to a heap overflow and an out-of-bounds write. Successful exploitation could result in an application level denial of service."
    ],
    "statement": "This MODERATE impact flaw in GIMP's PSP image file parser can lead to an application level denial of service. The vulnerability occurs when processing a specially crafted PSP image, which can cause a heap overflow and out-of-bounds write.",
    "acknowledgement": "Red Hat would like to thank wooseokdotkim for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gimp:2.8/gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2271\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2271\nhttps://gitlab.gnome.org/GNOME/gimp/-/issues/15732"
    ],
    "name": "CVE-2026-2271",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-10T09:09:00Z",
    "bugzilla": {
      "description": "gimp: GIMP: Memory corruption due to integer overflow in ICO file handling",
      "id": "2438428",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2438428"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read_icon` functions. This issue arises because a size calculation for image buffers can wrap around due to a 32-bit integer evaluation, allowing oversized image headers to bypass security checks. A remote attacker could exploit this by providing a specially crafted ICO file, leading to a buffer overflow and memory corruption, which may result in an application level denial of service.",
      "A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read_icon` functions. This issue arises because a size calculation for image buffers can wrap around due to a 32-bit integer evaluation, allowing oversized image headers to bypass security checks. A remote attacker could exploit this by providing a specially crafted ICO file, leading to a buffer overflow and memory corruption, which may result in an application level denial of service."
    ],
    "statement": "This MODERATE impact flaw in GIMP allows a remote attacker to cause an application denial of service. The vulnerability occurs due to an integer overflow when processing specially crafted ICO image files, leading to memory corruption. User interaction is required for exploitation, as a malicious ICO file must be opened by the GIMP application.",
    "acknowledgement": "Red Hat would like to thank Dhiraj Mishra for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gimp:2.8/gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2272\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2272\nhttps://gitlab.gnome.org/GNOME/gimp/-/issues/15617"
    ],
    "name": "CVE-2026-2272",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-01-27T00:00:00Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing",
      "id": "2430389",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-843",
    "details": [
      "Issue summary: An invalid or NULL pointer dereference can happen in\nan application processing a malformed PKCS#12 file.\nImpact summary: An application processing a malformed PKCS#12 file can be\ncaused to dereference an invalid or NULL pointer on memory read, resulting\nin a Denial of Service.\nA type confusion vulnerability exists in PKCS#12 parsing code where\nan ASN1_TYPE union member is accessed without first validating the type,\ncausing an invalid pointer read.\nThe location is constrained to a 1-byte address space, meaning any\nattempted pointer manipulation can only target addresses between 0x00 and 0xFF.\nThis range corresponds to the zero page, which is unmapped on most modern\noperating systems and will reliably result in a crash, leading only to a\nDenial of Service. Exploiting this issue also requires a user or application\nto process a maliciously crafted PKCS#12 file. It is uncommon to accept\nuntrusted PKCS#12 files in applications as they are usually used to store\nprivate keys which are trusted by definition. For these reasons, the issue\nwas assessed as Low severity.\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS12 implementation is outside the OpenSSL FIPS module boundary.\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\nOpenSSL 1.0.2 is not affected by this issue.",
      "A flaw was found in OpenSSL. This type confusion vulnerability allows a remote attacker to cause a Denial of Service (DoS) by tricking a user or application into processing a maliciously crafted PKCS#12 (Personal Information Exchange Syntax Standard) file. The vulnerability leads to an invalid or NULL pointer dereference, resulting in an application crash."
    ],
    "statement": "This vulnerability is rated Low for Red Hat products. An application processing a maliciously crafted PKCS#12 file can be caused to dereference an invalid or NULL pointer, resulting in a Denial of Service. In the Red Hat context, impact is limited as PKCS#12 files are typically used for trusted private keys and are not commonly accepted from untrusted sources.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1472",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssl-1:3.5.1-7.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Cost Management Metrics Operator 4",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3228",
        "cpe": "cpe:/a:redhat:cost_management:4::el9",
        "package": "costmanagement/costmanagement-metrics-rhel9-operator:1770836349"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1769104765"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1769111774"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7261",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssl-main-3.5.6-0.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2485",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1770740405"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2563",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1770646925"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1773670073"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1773672059"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1773670137"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-22795\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-22795"
    ],
    "name": "CVE-2026-22795",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-01-27T00:00:00Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification",
      "id": "2430390",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1287",
    "details": [
      "Issue summary: A type confusion vulnerability exists in the signature\nverification of signed PKCS#7 data where an ASN1_TYPE union member is\naccessed without first validating the type, causing an invalid or NULL\npointer dereference when processing malformed PKCS#7 data.\nImpact summary: An application performing signature verification of PKCS#7\ndata or calling directly the PKCS7_digest_from_attributes() function can be\ncaused to dereference an invalid or NULL pointer when reading, resulting in\na Denial of Service.\nThe function PKCS7_digest_from_attributes() accesses the message digest attribute\nvalue without validating its type. When the type is not V_ASN1_OCTET_STRING,\nthis results in accessing invalid memory through the ASN1_TYPE union, causing\na crash.\nExploiting this vulnerability requires an attacker to provide a malformed\nsigned PKCS#7 to an application that verifies it. The impact of the\nexploit is just a Denial of Service, the PKCS7 API is legacy and applications\nshould be using the CMS API instead. For these reasons the issue was\nassessed as Low severity.\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#7 parsing implementation is outside the OpenSSL FIPS module\nboundary.\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
      "A flaw was found in OpenSSL. This type confusion vulnerability allows a remote attacker to cause a denial of service (DoS) by providing specially crafted PKCS#7 data to an application that performs signature verification. The vulnerability occurs because the application accesses an ASN1_TYPE union member without proper type validation, leading to an invalid or NULL pointer dereference and a crash."
    ],
    "statement": "This vulnerability is rated Low for Red Hat products. A type confusion flaw in the legacy PKCS#7 API can lead to a Denial of Service when processing specially crafted PKCS#7 data. Exploitation requires an application to perform signature verification of malformed PKCS#7 data. Red Hat products utilizing the FIPS module are not affected as the PKCS#7 parsing is outside the module boundary.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1472",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssl-1:3.5.1-7.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-01-28T00:00:00Z",
        "advisory": "RHSA-2026:1473",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.1-7.el9_7"
      },
      {
        "product_name": "Cost Management Metrics Operator 4",
        "release_date": "2026-02-24T00:00:00Z",
        "advisory": "RHSA-2026:3228",
        "cpe": "cpe:/a:redhat:cost_management:4::el9",
        "package": "costmanagement/costmanagement-metrics-rhel9-operator:1770836349"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1769104765"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-02-02T00:00:00Z",
        "advisory": "RHSA-2026:1736",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1769111774"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7261",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssl-main-3.5.6-0.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2485",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1770740405"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-02-11T00:00:00Z",
        "advisory": "RHSA-2026:2563",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1770646925"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1773670073"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1773672059"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1773670137"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-22796\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-22796"
    ],
    "name": "CVE-2026-22796",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-09T00:00:00Z",
    "bugzilla": {
      "description": "dnsmasq: dnsmasq: heap buffer overflow in cache via NAME_ESCAPE expansion",
      "id": "2439088",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2439088"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.",
      "A heap buffer overflow was discovered in dnsmasq's DNS cache. When processing DNS responses, dnsmasq expands certain characters into longer escape sequences, but the cache buffer is not sized to hold the expanded result. A specially crafted DNS response can overflow this buffer, potentially crashing the dnsmasq process or poisoning DNS cache records."
    ],
    "statement": "Red Hat rates this issue as Moderate rather than Important. While DNS cache poisoning is possible, a process crash is the most likely outcome of a successful exploit. Also, standard upstream DNS resolvers reject the malformed responses before they reach dnsmasq, limiting exploitation to uncommon configurations where dnsmasq forwards directly to an attacker-controlled server.",
    "acknowledgement": "Red Hat would like to thank Andrew Fasano (NIST) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19158",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "dnsmasq-0:2.90-7.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20589",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "dnsmasq-0:2.79-36.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19373",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "dnsmasq-0:2.85-18.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34508",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "dnsmasq-0:2.85-17.el9_6.1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:54553",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202608120446-0"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2291\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2291"
    ],
    "name": "CVE-2026-2291",
    "csaw": false
  },
  {
    "public_date": "2026-01-31T00:00:00Z",
    "bugzilla": {
      "description": "kernel: dmaengine: omap-dma: fix dma_pool resource leak in error paths",
      "id": "2435643",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2435643"
    },
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\ndmaengine: omap-dma: fix dma_pool resource leak in error paths\nThe dma_pool created by dma_pool_create() is not destroyed when\ndma_async_device_register() or of_dma_controller_register() fails,\ncausing a resource leak in the probe error paths.\nAdd dma_pool_destroy() in both error paths to properly release the\nallocated dma_pool resource."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-23033\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-23033\nhttps://lore.kernel.org/linux-cve-announce/2026013121-CVE-2026-23033-c543@gregkh/T"
    ],
    "name": "CVE-2026-23033",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-04T00:00:00Z",
    "bugzilla": {
      "description": "kernel: Linux kernel: Denial of Service in ems_usb CAN USB driver due to memory leak",
      "id": "2436788",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436788"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-401",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\ncan: ems_usb: ems_usb_read_bulk_callback(): fix URB memory leak\nFix similar memory leak as in commit 7352e1d5932a (\"can: gs_usb:\ngs_usb_receive_bulk_callback(): fix URB memory leak\").\nIn ems_usb_open(), the URBs for USB-in transfers are allocated, added to\nthe dev->rx_submitted anchor and submitted. In the complete callback\nems_usb_read_bulk_callback(), the URBs are processed and resubmitted. In\nems_usb_close() the URBs are freed by calling\nusb_kill_anchored_urbs(&dev->rx_submitted).\nHowever, this does not take into account that the USB framework unanchors\nthe URB before the complete function is called. This means that once an\nin-URB has been completed, it is no longer anchored and is ultimately not\nreleased in ems_usb_close().\nFix the memory leak by anchoring the URB in the\nems_usb_read_bulk_callback() to the dev->rx_submitted anchor.",
      "A flaw was found in the Linux kernel's ems_usb Controller Area Network (CAN) Universal Serial Bus (USB) driver. A local user with access to the CAN network interface can repeatedly trigger open and close cycles, leading to a memory leak. This occurs because completed USB Request Blocks (URBs) are unanchored by the USB core before the completion callback runs, preventing proper cleanup. Over time, this resource exhaustion can lead to a denial of service."
    ],
    "statement": "A memory leak can occur in the ems_usb CAN USB driver because completed RX URBs are unanchored by the USB core before the completion callback runs. The driver anchored URBs only during open and then relied on usb_kill_anchored_urbs during close to free them. Once an URB completes it is no longer in the rx_submitted anchor and it can escape cleanup which leads to leaked URB allocations over repeated activity and open close cycles. For the CVSS the PR is L in the paranoid rating because a user with access to the CAN network interface can often trigger open close or device use through standard networking administration in delegated environments. The issue is not directly network reachable in the IP sense. Impact is denial of service via resource exhaustion over time.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-23058\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-23058\nhttps://lore.kernel.org/linux-cve-announce/2026020414-CVE-2026-23058-802c@gregkh/T"
    ],
    "name": "CVE-2026-23058",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-02-04T00:00:00Z",
    "bugzilla": {
      "description": "kernel: net/sched: act_ife: avoid possible NULL deref",
      "id": "2436798",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436798"
    },
    "cvss3": {
      "cvss3_base_score": "4.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-476",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nnet/sched: act_ife: avoid possible NULL deref\ntcf_ife_encode() must make sure ife_encode() does not return NULL.\nsyzbot reported:\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI\nKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\nRIP: 0010:ife_tlv_meta_encode+0x41/0xa0 net/ife/ife.c:166\nCPU: 3 UID: 0 PID: 8990 Comm: syz.0.696 Not tainted syzkaller #0 PREEMPT(full)\nCall Trace:\n<TASK>\nife_encode_meta_u32+0x153/0x180 net/sched/act_ife.c:101\ntcf_ife_encode net/sched/act_ife.c:841 [inline]\ntcf_ife_act+0x1022/0x1de0 net/sched/act_ife.c:877\ntc_act include/net/tc_wrapper.h:130 [inline]\ntcf_action_exec+0x1c0/0xa20 net/sched/act_api.c:1152\ntcf_exts_exec include/net/pkt_cls.h:349 [inline]\nmall_classify+0x1a0/0x2a0 net/sched/cls_matchall.c:42\ntc_classify include/net/tc_wrapper.h:197 [inline]\n__tcf_classify net/sched/cls_api.c:1764 [inline]\ntcf_classify+0x7f2/0x1380 net/sched/cls_api.c:1860\nmultiq_classify net/sched/sch_multiq.c:39 [inline]\nmultiq_enqueue+0xe0/0x510 net/sched/sch_multiq.c:66\ndev_qdisc_enqueue+0x45/0x250 net/core/dev.c:4147\n__dev_xmit_skb net/core/dev.c:4262 [inline]\n__dev_queue_xmit+0x2998/0x46c0 net/core/dev.c:4798",
      "A NULL pointer dereference vulnerability was found in the Linux kernel's traffic control IFE (Inter-FE) action module. The tcf_ife_encode() function fails to verify that ife_encode() returns a valid pointer before use. When ife_encode() returns NULL, subsequent calls to ife_tlv_meta_encode() attempt to dereference the NULL pointer, triggering a kernel crash during packet processing."
    ],
    "statement": "This vulnerability was discovered by syzkaller and affects systems using the tc (traffic control) IFE action for inter-forwarding-element metadata encapsulation. Triggering this flaw requires the ability to configure traffic control rules, typically requiring root or CAP_NET_ADMIN privileges. The impact is denial of service through a kernel crash during packet transmission.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-23064\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-23064\nhttps://lore.kernel.org/linux-cve-announce/2026020416-CVE-2026-23064-8eec@gregkh/T"
    ],
    "name": "CVE-2026-23064",
    "mitigation": {
      "value": "To mitigate this issue, prevent the act_ife module from being loaded if IFE traffic control actions are not required. See https://access.redhat.com/solutions/41278 for instructions on how to blacklist a kernel module.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "public_date": "2026-02-04T00:00:00Z",
    "bugzilla": {
      "description": "kernel: wifi: rsi: Fix memory corruption due to not set vif driver data size",
      "id": "2436783",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436783"
    },
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nwifi: rsi: Fix memory corruption due to not set vif driver data size\nThe struct ieee80211_vif contains trailing space for vif driver data,\nwhen struct ieee80211_vif is allocated, the total memory size that is\nallocated is sizeof(struct ieee80211_vif) + size of vif driver data.\nThe size of vif driver data is set by each WiFi driver as needed.\nThe RSI911x driver does not set vif driver data size, no trailing space\nfor vif driver data is therefore allocated past struct ieee80211_vif .\nThe RSI911x driver does however use the vif driver data to store its\nvif driver data structure \"struct vif_priv\". An access to vif->drv_priv\nleads to access out of struct ieee80211_vif bounds and corruption of\nsome memory.\nIn case of the failure observed locally, rsi_mac80211_add_interface()\nwould write struct vif_priv *vif_info = (struct vif_priv *)vif->drv_priv;\nvif_info->vap_id = vap_idx. This write corrupts struct fq_tin member\nstruct list_head new_flows . The flow = list_first_entry(head, struct\nfq_flow, flowchain); in fq_tin_reset() then reports non-NULL bogus\naddress, which when accessed causes a crash.\nThe trigger is very simple, boot the machine with init=/bin/sh , mount\ndevtmpfs, sysfs, procfs, and then do \"ip link set wlan0 up\", \"sleep 1\",\n\"ip link set wlan0 down\" and the crash occurs.\nFix this by setting the correct size of vif driver data, which is the\nsize of \"struct vif_priv\", so that memory is allocated and the driver\ncan store its driver data in it, instead of corrupting memory around\nit."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-23073\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-23073\nhttps://lore.kernel.org/linux-cve-announce/2026020419-CVE-2026-23073-9fce@gregkh/T"
    ],
    "name": "CVE-2026-23073",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-02-04T00:00:00Z",
    "bugzilla": {
      "description": "kernel: netrom: Denial of Service via double-free vulnerability in nr_route_frame()",
      "id": "2436810",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436810"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-1341",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nnetrom: fix double-free in nr_route_frame()\nIn nr_route_frame(), old_skb is immediately freed without checking if\nnr_neigh->ax25 pointer is NULL. Therefore, if nr_neigh->ax25 is NULL,\nthe caller function will free old_skb again, causing a double-free bug.\nTherefore, to prevent this, we need to modify it to check whether\nnr_neigh->ax25 is NULL before freeing old_skb.",
      "A flaw was found in netrom. In the Linux kernel's netrom component, a double-free vulnerability exists within the `nr_route_frame()` function. This occurs because the `old_skb` object is freed without properly checking if a related pointer (`nr_neigh->ax25`) is null. If the pointer is null, the system attempts to free the same memory again, which can lead to a system crash and a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-23098\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-23098\nhttps://lore.kernel.org/linux-cve-announce/2026020427-CVE-2026-23098-1fd2@gregkh/T"
    ],
    "name": "CVE-2026-23098",
    "csaw": false
  },
  {
    "public_date": "2026-02-14T00:00:00Z",
    "bugzilla": {
      "description": "kernel: platform/x86: toshiba_haps: Fix memory leaks in add/remove routines",
      "id": "2439881",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2439881"
    },
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nplatform/x86: toshiba_haps: Fix memory leaks in add/remove routines\ntoshiba_haps_add() leaks the haps object allocated by it if it returns\nan error after allocating that object successfully.\ntoshiba_haps_remove() does not free the object pointed to by\ntoshiba_haps before clearing that pointer, so it becomes unreachable\nallocated memory.\nAddress these memory leaks by using devm_kzalloc() for allocating\nthe memory in question."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-23176\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-23176\nhttps://lore.kernel.org/linux-cve-announce/2026021428-CVE-2026-23176-4baf@gregkh/T"
    ],
    "name": "CVE-2026-23176",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-05T16:36:05Z",
    "bugzilla": {
      "description": "redis: use-after-free in unblock client flow may allow remote code execution",
      "id": "2466780",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466780"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-416",
    "details": [
      "Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.",
      "A flaw was found in Redis. The unblock client flow does not handle an error return from the `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can cause a use-after-free issue. This potentially leads to arbitrary code execution."
    ],
    "statement": "To exploit this flaw, a highly specific sequence of events and time dependent conditions that are not directly in control of an attacker must occur, increasing the complexity of exploitation. Additionally, the attacker needs to be authenticated, limiting the exposure of this issue. To reflect these conditions, this vulnerability has been rated with an important severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25216",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "valkey-0:8.0.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26540",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "valkey-0:8.0.9-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25219",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "redis:7-9080020260521083756.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25925",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "valkey-0:8.0.9-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26306",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "redis:7-9060020260602115714.9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14316",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "valkey-main-9.0.4-0.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-11T00:00:00Z",
        "advisory": "RHSA-2026:7662",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "boost-main-1.90.0-7.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "redis:6/redis",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "redis",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-23479\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-23479\nhttps://github.com/redis/redis/releases/tag/8.6.3\nhttps://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3"
    ],
    "name": "CVE-2026-23479",
    "mitigation": {
      "value": "Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-01-16T19:03:36Z",
    "bugzilla": {
      "description": "pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID",
      "id": "2430472",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430472"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.",
      "A flaw was found in pyasn1, a generic ASN.1 library for Python. A remote attacker could exploit this vulnerability by sending a specially crafted RELATIVE-OID with excessive continuation octets. This input validation vulnerability leads to memory exhaustion, resulting in a Denial of Service (DoS) for the affected system."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13512",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "python3.12-pyasn1-0:0.6.3-1.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-03-06T00:00:00Z",
        "advisory": "RHSA-2026:3959",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "automation-controller-0:4.6.26-1.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13512",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "python3.12-pyasn1-0:0.6.3-1.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-03-06T00:00:00Z",
        "advisory": "RHSA-2026:3959",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "automation-controller-0:4.6.26-1.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13508",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "python3.12-pyasn1-0:0.6.3-1.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-03-06T00:00:00Z",
        "advisory": "RHSA-2026:3958",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "automation-controller-0:4.7.9-1.el9ap"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1905",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "fence-agents-0:4.16.0-13.el10_1.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3354",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "python-pyasn1-0:0.6.2-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2309",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "fence-agents-0:4.16.0-5.el10_0.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4138",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "python-pyasn1-0:0.6.2-1.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2758",
        "cpe": "cpe:/a:redhat:rhel_extras_sap_els:7",
        "package": "resource-agents-0:4.1.1-61.el7_9.23"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2758",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "package": "resource-agents-0:4.1.1-61.el7_9.23"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4148",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "python-pyasn1-0:0.1.9-7.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1906",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "fence-agents-0:4.2.1-129.el8_10.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4146",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python-pyasn1-0:0.3.7-6.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1904",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::highavailability",
        "package": "resource-agents-0:4.9.0-54.el8_10.28"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4145",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "python-pyasn1-0:0.3.7-6.el8_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2483",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "fence-agents-0:4.2.1-65.el8_4.27"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4147",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "python-pyasn1-0:0.3.7-6.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2712",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4::highavailability",
        "package": "resource-agents-0:4.1.1-90.el8_4.23"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2483",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "fence-agents-0:4.2.1-65.el8_4.27"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4147",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "python-pyasn1-0:0.3.7-6.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-02-16T00:00:00Z",
        "advisory": "RHSA-2026:2712",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4::highavailability",
        "package": "resource-agents-0:4.1.1-90.el8_4.23"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2486",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "fence-agents-0:4.2.1-89.el8_6.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4144",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "python-pyasn1-0:0.3.7-6.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2486",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "fence-agents-0:4.2.1-89.el8_6.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4144",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "python-pyasn1-0:0.3.7-6.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2453",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6::highavailability",
        "package": "resource-agents-0:4.9.0-16.el8_6.20"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2486",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "fence-agents-0:4.2.1-89.el8_6.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4144",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "python-pyasn1-0:0.3.7-6.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2453",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6::highavailability",
        "package": "resource-agents-0:4.9.0-16.el8_6.20"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2221",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "fence-agents-0:4.2.1-112.el8_8.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4139",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "python-pyasn1-0:0.3.7-6.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2460",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8::highavailability",
        "package": "resource-agents-0:4.9.0-40.el8_8.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2221",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "fence-agents-0:4.2.1-112.el8_8.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4139",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "python-pyasn1-0:0.3.7-6.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-02-10T00:00:00Z",
        "advisory": "RHSA-2026:2460",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8::highavailability",
        "package": "resource-agents-0:4.9.0-40.el8_8.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-04T00:00:00Z",
        "advisory": "RHSA-2026:1903",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "fence-agents-0:4.10.0-98.el9_7.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3359",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python-pyasn1-0:0.4.8-7.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2303",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "fence-agents-0:4.10.0-20.el9_0.28"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4140",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "python-pyasn1-0:0.4.8-6.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2300",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "fence-agents-0:4.10.0-43.el9_2.19"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4142",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "python-pyasn1-0:0.4.8-6.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2302",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "fence-agents-0:4.10.0-62.el9_4.22"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4143",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python-pyasn1-0:0.4.8-6.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-09T00:00:00Z",
        "advisory": "RHSA-2026:2299",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "fence-agents-0:4.10.0-86.el9_6.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4141",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "python-pyasn1-0:0.4.8-6.el9_6.1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17595",
        "cpe": "cpe:/a:redhat:openshift_ironic:4.17::el9",
        "package": "python-pyasn1-0:0.5.1-4.el9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17446",
        "cpe": "cpe:/a:redhat:openshift_ironic:4.18::el9",
        "package": "python-pyasn1-0:0.5.1-4.el9"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54757",
        "cpe": "cpe:/a:redhat:openstack:16.2::el8",
        "package": "python-pyasn1-0:0.4.6-4.el8ost"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1 for RHEL 8",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:28042",
        "cpe": "cpe:/a:redhat:openstack:17.1::el8",
        "package": "python-pyasn1-0:0.4.6-5.el8ost"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30088",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782353093"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13553",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "ansible-automation-platform-25/ee-supported-rhel8:1777398315"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13553",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "ansible-automation-platform-25/platform-resource-runner-rhel8:1777402264"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/eda-controller-rhel9:1777296732"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/ee-supported-rhel9:1777391447"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-06-09T00:00:00Z",
        "advisory": "RHSA-2026:24866",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-chatbot-rhel9:1780102732"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5606",
        "cpe": "cpe:/a:redhat:ceph_storage:8::el9",
        "package": "rhceph/rhceph-8-rhel9:1774002867"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17611",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-azure-rocm-rhel9:1778677745"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17611",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-rocm-rhel9:1778666124"
      },
      {
        "product_name": "Red Hat Migration Toolkit 1.8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41928",
        "cpe": "cpe:/a:redhat:rhmt:1.8::el8",
        "package": "rhmtc/openshift-migration-hook-runner-rhel8:1783931722"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-feature-server-rhel9:1780069135"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-kserve-storage-initializer-rhel9:1780069127"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1783696512"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9:1783696506"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1783616068"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1783998551"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1783615385"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1783664921"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1783696507"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9:1783696510"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9:1783664711"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9:1783664922"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1783615414"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1783998585"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1783664921"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1783615165"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1783664921"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1783615432"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-feature-server-rhel9:1778239104"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-kserve-storage-initializer-rhel9:1778263407"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-mlflow-rhel9:1778791600"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-cuda128-torch29-py312-rhel9:1779123334"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-llama-stack-core-rhel9:1782471587"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1782471672"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9:1782471678"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1782471731"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1782471732"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:1782471849"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1782471734"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1782471879"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9:1782472374"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9:1782471606"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1782471796"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1782471661"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9:1782471672"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9:1782471731"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9:1782471929"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1782471753"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1782471740"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1782471834"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1782471730"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1782471835"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1782471697"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39894",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/ee-openstack-ansible-ee-rhel9:1782387549"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24476",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/segment-reporting-rhel9:1780560117"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.4",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24483",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.4::el9",
        "package": "rhtas/model-transparency-rhel9:1780914886"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-03-18T00:00:00Z",
        "advisory": "RHSA-2026:4943",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1773670137"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14020",
        "cpe": "cpe:/a:redhat:stf:1.5::el9",
        "package": "stf/prometheus-webhook-snmp-rhel9:1777452540"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14020",
        "cpe": "cpe:/a:redhat:stf:1.5::el9",
        "package": "stf/service-telemetry-rhel9-operator:1777407251"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14020",
        "cpe": "cpe:/a:redhat:stf:1.5::el9",
        "package": "stf/smart-gateway-rhel9-operator:1777436150"
      }
    ],
    "package_state": [
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Affected",
        "package_name": "lightspeed-core/dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Affected",
        "package_name": "lightspeed-core/lightspeed-stack-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-rhel8-operator",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Will not fix",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3.11-pyasn1",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3.11-pyasn1-modules",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3.12-pyasn1-modules",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3x-pyasn1",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ztp-site-generate-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Will not fix",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "python3.12-pyasn1",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Will not fix",
        "package_name": "python3.12-pyasn1-modules",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "python-pyasn1-modules",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "satellite/iop-insights-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-23490\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-23490\nhttps://github.com/pyasn1/pyasn1/commit/3908f144229eed4df24bd569d16e5991ace44970\nhttps://github.com/pyasn1/pyasn1/releases/tag/v0.6.2\nhttps://github.com/pyasn1/pyasn1/security/advisories/GHSA-63vm-454h-vhhq"
    ],
    "name": "CVE-2026-23490",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-05T16:39:32Z",
    "bugzilla": {
      "description": "redis: Remote code execution via use-after-free in Lua scripting",
      "id": "2466788",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466788"
    },
    "cvss3": {
      "cvss3_base_score": "8.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-416",
    "details": [
      "Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.",
      "A flaw was found in Redis, an in-memory data structure store. An authenticated attacker can exploit a use-after-free vulnerability in redis-server with Lua scripting. This occurs through the master-replica synchronization mechanism on replicas where replica-read-only is disabled or can be disabled. Successful exploitation may lead to remote code execution."
    ],
    "statement": "This Important vulnerability in Redis affects instances configured with Lua scripting and operating as replicas where the `replica-read-only` setting is disabled or can be modified by an authenticated attacker. Exploitation of a use-after-free flaw during master-replica synchronization could lead to remote code execution. The risk is present in deployments where Redis replicas are configured for write operations or lack sufficient access controls to prevent modification of the `replica-read-only` setting.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25216",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "valkey-0:8.0.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26540",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "valkey-0:8.0.9-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25219",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "redis:7-9080020260521083756.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25925",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "valkey-0:8.0.9-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33444",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "redis:7-9040020260625094332.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26306",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "redis:7-9060020260602115714.9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14316",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "valkey-main-9.0.4-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "redis:6/redis",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "redis",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "boost",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-23631\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-23631\nhttps://github.com/redis/redis/releases/tag/8.6.3\nhttps://github.com/redis/redis/security/advisories/GHSA-8ghh-qpmp-7826"
    ],
    "name": "CVE-2026-23631",
    "mitigation": {
      "value": "To mitigate this flaw, ensure that Redis replicas maintain `replica-read-only` as enabled and prevent its modification by unauthorized users. If Lua scripting is not a required feature, consider disabling it to reduce the attack surface. Restricting network access to Redis instances to trusted clients can also limit exposure.\nFor Redis configuration, edit the `redis.conf` file to include or verify:\n`replica-read-only yes`\nAfter modifying the configuration, restart the Redis service for the changes to take effect. This action will temporarily interrupt service availability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-11T11:11:00Z",
    "bugzilla": {
      "description": "libsoup: libsoup: Buffer overread due to integer underflow when handling zero-length resources",
      "id": "2439091",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2439091"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-191",
    "details": [
      "A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application level denial of service.",
      "A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application level denial of service."
    ],
    "statement": "This MODERATE impact flaw in libsoup arises from an integer underflow when processing content with zero-length resources, leading to a buffer overread. This vulnerability could allow an attacker to potentially access sensitive information or cause an application-level denial of service. Red Hat Enterprise Linux and Fedora systems utilizing libsoup are affected when applications process such malformed content.",
    "acknowledgement": "Red Hat would like to thank Eric Su and Samuel Dainard for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libsoup3",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2369\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2369\nhttps://gitlab.gnome.org/GNOME/libsoup/-/issues/498"
    ],
    "name": "CVE-2026-2369",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-09T18:12:00Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2()",
      "id": "2438207",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2438207"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, a NULL pointer dereference vulnerability in rdp_write_logon_info_v2() allows a malicious RDP server to crash FreeRDP proxy by sending a specially crafted LogonInfoV2 PDU with cbDomain=0 or cbUserName=0. This vulnerability is fixed in 3.22.0.",
      "A null pointer dereference has been discovered in FreeRDP. A NULL pointer dereference vulnerability in rdp_write_logon_info_v2() allows a malicious RDP server to crash FreeRDP proxy by sending a specially crafted LogonInfoV2 PDU with cbDomain=0 or cbUserName=0."
    ],
    "statement": "Availability impact is limited to the FreeRDP instance on Red Hat Products. General system availability is not at risk.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6799",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "freerdp-2:3.10.3-5.el10_1.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19033",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freerdp-2:3.10.3-12.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6743",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freerdp-2:3.10.3-3.el10_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11323",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "freerdp-0:2.1.1-5.el7_9.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6918",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "freerdp-2:2.11.7-6.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10734",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "freerdp-2:2.0.0-46.rc4.el8_2.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10735",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "freerdp-2:2.2.0-12.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10735",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "freerdp-2:2.2.0-12.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10951",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10951",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10951",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10076",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10076",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6340",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-1.el9_7.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9640",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "freerdp-2:2.4.1-3.el9_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9641",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freerdp-2:2.4.1-6.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:6958",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "freerdp-2:2.11.2-1.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6727",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freerdp-2:2.11.7-1.el9_6.7"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-23948\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-23948\nhttps://github.com/FreeRDP/FreeRDP/commit/4d44e3c097656a8b9ec696353647b0888ca45860\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6f3c-qvqq-2px5"
    ],
    "name": "CVE-2026-23948",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-04T12:37:57Z",
    "bugzilla": {
      "description": "Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation",
      "id": "2464941",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464941"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-73",
    "details": [
      "An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.",
      "A flaw was found in Apache HTTP Server. This escalation of privilege vulnerability allows local attackers, specifically those with the ability to author .htaccess files, to read sensitive files. This flaw enables unauthorized access to files with the privileges of the httpd user, potentially leading to information disclosure."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34109",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41906",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.5"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13938",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.67-0.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "httpd:2.4/httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Affected",
        "package_name": "jbcs-httpd24-httpd",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-24072\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-24072\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-24072",
    "mitigation": {
      "value": "To prevent local users from exploiting this flaw via .htaccess file manipulation, configure Apache HTTP Server to disable .htaccess overrides. Set `AllowOverride None` within the main server configuration or relevant `<Directory>` blocks. This restricts the ability of local users to alter server settings. After applying this change, the `httpd` service must be reloaded or restarted for the new configuration to take effect.\nExample configuration:\n```\n<Directory \"/var/www/html\">\nAllowOverride None\n</Directory>\n```\nTo apply changes, reload the service:\n`sudo systemctl reload httpd`\nOr restart the service:\n`sudo systemctl restart httpd`",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-24T01:25:02Z",
    "bugzilla": {
      "description": "avahi: Avahi: Denial of Service via recursive CNAME record in mDNS response",
      "id": "2432534",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2432534"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-674",
    "details": [
      "Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.",
      "A flaw was found in Avahi, a system that enables devices to discover services on a local network. A remote attacker can exploit this vulnerability by sending a specially crafted mDNS (multicast Domain Name System) response containing a recursive CNAME (Canonical Name) record. This triggers an uncontrolled recursion within the avahi-daemon process, leading to stack exhaustion and causing the service to crash. This results in a denial of service (DoS) for affected systems."
    ],
    "statement": "This MODERATE impact flaw in Avahi's `avahi-daemon` can lead to a denial of service. An attacker on the local network could send a specially crafted, unsolicited mDNS response containing a recursive CNAME record, causing unbounded recursion and a crash. This affects systems where Avahi's record browsers explicitly use multicast, such as those utilizing `nss-mdns`.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11316",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "avahi-main-0.9~rc4-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "avahi",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-24401\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-24401\nhttps://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524\nhttps://github.com/avahi/avahi/issues/501\nhttps://github.com/avahi/avahi/security/advisories/GHSA-h4vp-5m8j-f6w3"
    ],
    "name": "CVE-2026-24401",
    "mitigation": {
      "value": "To mitigate this issue, disable the avahi-daemon service if mDNS/DNS-SD functionality is not required on the system.\n```bash\nsudo systemctl disable --now avahi-daemon.service\nsudo systemctl mask avahi-daemon.service\n```\nDisabling this service may impact applications relying on mDNS for local network service discovery. A system reboot or service reload may be required for the changes to take full effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-02-13T00:00:00Z",
    "bugzilla": {
      "description": "libsoup: Out-of-Bounds Read in libsoup handle_partial_get() Leading to Heap Information Disclosure",
      "id": "2439671",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2439671"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.",
      "A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component."
    ],
    "statement": "This issue has a LOW impact. An out-of-bounds read vulnerability in libsoup, when processing HTTP Range headers, can lead to heap information disclosure. Although upstream exploitation may allow disclosure of heap memory contents, Red Hat does not build GLib with G_DISABLE_CHECKS, which prevents creation of out-of-bounds byte slices in supported products. As a result, the risk of meaningful information disclosure in shipped configurations is limited. The issue primarily affects applications exposing the SoupServer component and processing untrusted HTTP Range headers.",
    "acknowledgement": "Red Hat would like to thank Codean Labs for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libsoup3",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2443\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2443\nhttps://gitlab.gnome.org/GNOME/libsoup/-/issues/487"
    ],
    "name": "CVE-2026-2443",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-02-16T14:13:23Z",
    "bugzilla": {
      "description": "libvpx: Heap buffer overflow in libvpx",
      "id": "2440219",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2440219"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "details": [
      "Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.",
      "A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Heap buffer overflow in libvpx."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3361",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "firefox-0:140.8.0-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3517",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "thunderbird-0:140.8.0-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-16T00:00:00Z",
        "advisory": "RHSA-2026:4629",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "libvpx-0:1.14.1-6.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3976",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "firefox-0:140.8.0-2.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:4260",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "thunderbird-0:140.8.0-2.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5227",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libvpx-0:1.14.1-3.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3984",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "firefox-0:140.8.0-2.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5320",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libvpx-0:1.3.0-8.el7_9.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3338",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "firefox-0:140.8.0-2.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3515",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "thunderbird-0:140.8.0-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3967",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libvpx-0:1.7.0-13.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3492",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "firefox-0:140.8.0-2.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4432",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "thunderbird-0:140.8.0-1.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5228",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "libvpx-0:1.7.0-8.el8_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3491",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "firefox-0:140.8.0-2.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3980",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "thunderbird-0:140.8.0-2.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5323",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libvpx-0:1.7.0-10.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3491",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "firefox-0:140.8.0-2.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3980",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "thunderbird-0:140.8.0-2.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5323",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libvpx-0:1.7.0-10.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3495",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "firefox-0:140.8.0-2.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3979",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "thunderbird-0:140.8.0-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5229",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libvpx-0:1.7.0-10.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3495",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "firefox-0:140.8.0-2.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3979",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "thunderbird-0:140.8.0-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5229",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "libvpx-0:1.7.0-10.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3495",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "firefox-0:140.8.0-2.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3979",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "thunderbird-0:140.8.0-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5229",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "libvpx-0:1.7.0-10.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3494",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "firefox-0:140.8.0-2.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:4022",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "thunderbird-0:140.8.0-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5230",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libvpx-0:1.7.0-10.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3494",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "firefox-0:140.8.0-2.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:4022",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "thunderbird-0:140.8.0-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5230",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libvpx-0:1.7.0-10.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-25T00:00:00Z",
        "advisory": "RHSA-2026:3339",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "firefox-0:140.8.0-2.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3516",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "thunderbird-0:140.8.0-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4447",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libvpx-0:1.9.0-10.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3493",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "firefox-0:140.8.0-2.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3983",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "thunderbird-0:140.8.0-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5326",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "libvpx-0:1.9.0-7.el9_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3978",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "thunderbird-0:140.8.0-1.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4152",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "firefox-0:140.8.0-2.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5319",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libvpx-0:1.9.0-7.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3496",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "firefox-0:140.8.0-2.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3981",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "thunderbird-0:140.8.0-1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5324",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "libvpx-0:1.9.0-7.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3497",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "firefox-0:140.8.0-2.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3982",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "thunderbird-0:140.8.0-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5231",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libvpx-0:1.9.0-9.el9_6.1"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8746",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1775680192"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8747",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1775680262"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8748",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1775749857"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "rhel10/firefox-flatpak",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libvpx",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2447\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2447\nhttps://bugzilla.mozilla.org/show_bug.cgi?id=2014390\nhttps://www.mozilla.org/security/advisories/mfsa2026-10/"
    ],
    "name": "CVE-2026-2447",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-07T13:49:25Z",
    "bugzilla": {
      "description": "LibRaw: LibRaw: Memory Corruption via Malicious File Processing",
      "id": "2455926",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455926"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.",
      "A flaw was found in LibRaw. A remote attacker could exploit a heap-based buffer overflow vulnerability in the x3f_load_huffman functionality by providing a specially crafted malicious file. This can lead to memory corruption, potentially allowing the attacker to execute arbitrary code or cause a denial of service."
    ],
    "statement": "LibRaw is not installed by default on Red Hat systems. A user would need to manually install and make available an affected code path for this vulnerability to be exploitable.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13284",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "LibRaw-0:0.19.5-6.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15926",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "LibRaw-0:0.19.5-2.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15926",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "LibRaw-0:0.19.5-2.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15925",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "LibRaw-0:0.19.5-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15925",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "LibRaw-0:0.19.5-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15925",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "LibRaw-0:0.19.5-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15924",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "LibRaw-0:0.19.5-3.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15924",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "LibRaw-0:0.19.5-3.el8_8.2"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Will not fix",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-24660\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-24660\nhttps://talosintelligence.com/vulnerability_reports/TALOS-2026-2359"
    ],
    "name": "CVE-2026-24660",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-02-17T18:50:43Z",
    "bugzilla": {
      "description": "tomcat: security constraint bypass with HTTP/0.9",
      "id": "2440437",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2440437"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-20",
    "details": [
      "Improper Input Validation vulnerability in Apache Tomcat.\nTomcat did not limit HTTP/0.9 requests to the GET method. If a security \nconstraint was configured to allow HEAD requests to a URI but deny GET \nrequests, the user could bypass that constraint on GET requests by \nsending a (specification invalid) HEAD request using HTTP/0.9.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112.\nOlder, EOL versions are also affected.\nUsers are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.",
      "A flaw was found in Tomcat. An improper input validation vulnerability allows an attacker to bypass security constraints. Specifically, if a security constraint is configured to permit HEAD requests to a URI but deny GET requests, a malformed or specification invalid HEAD request using the HTTP/0.9 protocol can bypass the intended denial rule, enabling an attacker to access resources that should be protected."
    ],
    "statement": "This flaw is only exploitable when Tomcat is configured to allow HEAD requests but deny GET requests to the same resource, a very unlikely configuration. Due to this reason, this flaw has been rated with a low severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36790",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "tomcat9-1:9.0.117-2.el10_2"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12195",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2",
        "package": "tomcat"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 10",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12194",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
        "package": "jws6-tomcat-0:10.1.49-10.redhat_00008.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 8",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12194",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
        "package": "jws6-tomcat-0:10.1.49-10.redhat_00008.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 9",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12194",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
        "package": "jws6-tomcat-0:10.1.49-10.redhat_00008.1.el9jws"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-04T00:00:00Z",
        "advisory": "RHSA-2026:6569",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.21-0.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8334",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.54-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-24733\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-24733\nhttps://lists.apache.org/thread/6xk3t65qpn1myp618krtfotbjn1qt90f"
    ],
    "name": "CVE-2026-24733",
    "mitigation": {
      "value": "To mitigate this vulnerability, ensure that security constraints are consistent across similar methods (e.g., if GET is denied, HEAD should likely be denied) or block HTTP/0.9 traffic via a reverse proxy or firewall, if it is not required.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-02-17T18:53:12Z",
    "bugzilla": {
      "description": "tomcat: Apache Tomcat: Certificate revocation bypass due to improper OCSP response validation",
      "id": "2440426",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2440426"
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-295",
    "details": [
      "Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat.\nWhen using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed.\nThis issue affects Apache Tomcat Native:  from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected.\nApache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue.\nApache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.",
      "A flaw was found in Apache Tomcat. When an Online Certificate Status Protocol (OCSP) responder is used, the Tomcat Native component, and Tomcat's FFM port of the Tomcat Native code, does not properly verify or check the freshness of the OCSP response. This improper input validation vulnerability could allow an attacker to bypass certificate revocation checks, potentially leading to the acceptance of revoked certificates."
    ],
    "statement": "This vulnerability doesn't affect the Apache Tomcat distributed with Red Hat Enterprise 8 and Red Hat Enterprise up to the version 9.7 as the vulnerable code is not built. The vulnerable code is compiled with Red Hat Enterprise Linux 9.8 and above.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19054",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "tomcat-1:10.1.49-1.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36790",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "tomcat9-1:9.0.117-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26323",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tomcat-1:9.0.117-1.el9_8"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2.1",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5612",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2",
        "package": "tomcat"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 10",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5611",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
        "package": "jws6-tomcat-0:10.1.49-9.redhat_00007.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 10",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5611",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
        "package": "jws6-tomcat-native-0:1.3.6-1.redhat_1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 8",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5611",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
        "package": "jws6-tomcat-0:10.1.49-9.redhat_00007.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 8",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5611",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
        "package": "jws6-tomcat-native-0:1.3.6-1.redhat_1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 9",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5611",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
        "package": "jws6-tomcat-0:10.1.49-9.redhat_00007.1.el9jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 9",
        "release_date": "2026-03-25T00:00:00Z",
        "advisory": "RHSA-2026:5611",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
        "package": "jws6-tomcat-native-0:1.3.6-1.redhat_1.el9jws"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-04T00:00:00Z",
        "advisory": "RHSA-2026:6569",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.21-0.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8334",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.54-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Will not fix",
        "package_name": "tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-24734\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-24734\nhttps://lists.apache.org/thread/292dlmx3fz1888v6v16221kpozq56gml"
    ],
    "name": "CVE-2026-24734",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-29T19:08:03Z",
    "bugzilla": {
      "description": "alsa-lib: alsa-lib Topology Decoder Heap-based Buffer Overflow",
      "id": "2435372",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2435372"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.",
      "alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7401",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "alsa-lib-main-1.2.15.3-3.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "alsa-lib",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "alsa-lib",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "alsa-lib",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "alsa-lib",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "alsa-lib",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-25068\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-25068\nhttps://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40\nhttps://www.vulncheck.com/advisories/alsa-lib-topology-decoder-heap-based-buffer-overflow"
    ],
    "name": "CVE-2026-25068",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-05T16:44:57Z",
    "bugzilla": {
      "description": "redis: RESTORE invalid memory access may allow remote code execution",
      "id": "2466828",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466828"
    },
    "cvss3": {
      "cvss3_base_score": "8.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-122",
    "details": [
      "Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This is patched in version 8.6.3.",
      "A flaw was found in Redis. An authenticated attacker with permission to execute the RESTORE command can send a crafted serialized payload that may lead to an invalid memory access due to an improper validation of the serialized values. This flaw can cause the server to crash and may allow arbitrary code execution."
    ],
    "statement": "To exploit this issue, an authenticated attacker with permission to execute the RESTORE command needs to send a specially crafted serialized payload to be processed by Redis, limiting its exposure to authenticated users. This allows the attacker to cause an invalid memory access, resulting in a denial of service or potentially in arbitrary code execution.\nDefault Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability.\nDue to these reasons, this vulnerability has been rated with an important severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25216",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "valkey-0:8.0.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26540",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "valkey-0:8.0.9-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:26008",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "redis:6-8100020260522105353.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27787",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "redis:6-8040020260618162855.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27787",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "redis:6-8040020260618162855.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29817",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "redis:6-8060020260623095617.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29817",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "redis:6-8060020260623095617.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33427",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "redis:6-8080020260626132343.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33427",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "redis:6-8080020260626132343.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23229",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "redis-0:6.2.22-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25219",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "redis:7-9080020260521083756.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25925",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "valkey-0:8.0.9-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27716",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "redis-0:6.2.7-1.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28139",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "redis-0:6.2.7-1.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28142",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "redis:7-9040020260618054637.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26233",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "redis-0:6.2.22-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26306",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "redis:7-9060020260602115714.9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14316",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "valkey-main-9.0.4-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "boost",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-25243\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-25243\nhttps://github.com/redis/redis/releases/tag/8.6.3\nhttps://github.com/redis/redis/security/advisories/GHSA-c8h9-259x-jff4"
    ],
    "name": "CVE-2026-25243",
    "mitigation": {
      "value": "To mitigate this flaw, restrict the execution privileges of the RESTORE command exclusively to highly trusted and administrative users by using the appropriate ACL rules.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-02-10T18:55:57Z",
    "bugzilla": {
      "description": "MUNGE: MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery",
      "id": "2438715",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2438715"
    },
    "cvss3": {
      "cvss3_base_score": "7.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.",
      "A buffer overflow vulnerability was discovered in the MUNGE authentication daemon (munged). In affected versions, a local attacker can potentially leak secret cryptographic key material from the daemon's memory by sending a specially crafted message with an oversized address field. With the leaked key, an attacker could forge authentication credentials to impersonate any user, potentially escalating privileges in systems that rely on MUNGE for identity verification."
    ],
    "statement": "An Important vulnerability was discovered in `munged`. A local attacker could sending a specially crafted message to leak cryptographic key material. This could enable them to forge MUNGE credentials and impersonate any user, including a system administrator. The impact of this vulnerability is less than Critical as it cannot be exploited remotely.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3033",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "munge-0:0.5.15-11.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2954",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "munge-0:0.5.15-10.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3032",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "munge-0:0.5.13-3.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-02-19T00:00:00Z",
        "advisory": "RHSA-2026:3011",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "munge-0:0.5.13-1.el8_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-02-19T00:00:00Z",
        "advisory": "RHSA-2026:3010",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "munge-0:0.5.13-2.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-02-19T00:00:00Z",
        "advisory": "RHSA-2026:3010",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "munge-0:0.5.13-2.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-02-19T00:00:00Z",
        "advisory": "RHSA-2026:3013",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "munge-0:0.5.13-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-02-19T00:00:00Z",
        "advisory": "RHSA-2026:3013",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "munge-0:0.5.13-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-02-19T00:00:00Z",
        "advisory": "RHSA-2026:3013",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "munge-0:0.5.13-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-02-19T00:00:00Z",
        "advisory": "RHSA-2026:3012",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "munge-0:0.5.13-2.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-02-19T00:00:00Z",
        "advisory": "RHSA-2026:3012",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "munge-0:0.5.13-2.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3034",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "munge-0:0.5.13-14.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2949",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "munge-0:0.5.13-13.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2934",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "munge-0:0.5.13-13.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2923",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "munge-0:0.5.13-13.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-02-18T00:00:00Z",
        "advisory": "RHSA-2026:2918",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "munge-0:0.5.13-13.el9_6.1"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-25506\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-25506\nhttps://github.com/dun/munge/commit/bf40cc27c4ce8451d4b062c9de0b67ec40894812\nhttps://github.com/dun/munge/releases/tag/munge-0.5.18\nhttps://github.com/dun/munge/security/advisories/GHSA-r9cr-jf4v-75gh"
    ],
    "name": "CVE-2026-25506",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-25T17:02:48Z",
    "bugzilla": {
      "description": "requests: Requests: Security bypass due to predictable temporary file creation",
      "id": "2451408",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451408"
    },
    "cvss3": {
      "cvss3_base_score": "4.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-379",
    "details": [
      "Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.",
      "A flaw was found in the `requests` HTTP library, specifically in the `requests.utils.extract_zipped_paths()` function, which is used to load Certificate Authority (CA) bundles. A local attacker can exploit this vulnerability by pre-creating a malicious CA bundle file in the system's temporary directory. When a vulnerable application initializes the `requests` library, it may load this malicious file instead of the legitimate CA bundle, leading to a bypass of security controls and potential integrity compromise."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat AI Inference Server 3.4",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57383",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.4::el9",
        "package": "rhaii/model-opt-cuda-rhel9:1787151832"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.4",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59144",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
        "package": "rhelai3/disk-image-cuda-rhel9:1787310717"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.4",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59151",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
        "package": "rhelai3/bootc-aws-cuda-rhel9:1787253912"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.4",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59151",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
        "package": "rhelai3/bootc-azure-cuda-rhel9:1787253989"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.4",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59151",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
        "package": "rhelai3/bootc-cuda-rhel9:1787243961"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.4",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59151",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
        "package": "rhelai3/bootc-gcp-cuda-rhel9:1787253774"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9:1786705347"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9-operator:1786706101"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-core-rhel9:1786705558"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-rhel9-operator:1786705646"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-console-rhel9:1786706138"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-rhel9-operator:1786705741"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1786705777"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-rhel9-operator:1786705802"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cli-rhel9:1786705938"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-console-rhel9:1786706577"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1786706125"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1786706177"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1786706188"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1786706679"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1786706357"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-must-gather-rhel9:1786706612"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-rhel9-operator:1786706644"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odr-rhel9-operator:1786706659"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1786706880"
      }
    ],
    "package_state": [
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/bitwarden-sdk-server-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-operator-bundle",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-operator-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Fix deferred",
        "package_name": "lightspeed-core/dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Fix deferred",
        "package_name": "lightspeed-core/lightspeed-stack-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Fix deferred",
        "package_name": "lightspeed-core/rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-curator5-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Fix deferred",
        "package_name": "rhmtc/openshift-migration-rhel8-operator",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Fix deferred",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Fix deferred",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:0"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis-preview/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ansible-dev-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat build of Quarkus Native builder",
        "fix_state": "Fix deferred",
        "package_name": "quarkus-mandrel#109bb34d7147bcc055f0f7f53427ebb8cb02f86d",
        "cpe": "cpe:/a:redhat:quarkus:3"
      },
      {
        "product_name": "Red Hat build of Quarkus Native builder",
        "fix_state": "Fix deferred",
        "package_name": "quarkus-mandrel#602dee7389eeb13bfb88aa7242da02d0161ee946",
        "cpe": "cpe:/a:redhat:quarkus:3"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Fix deferred",
        "package_name": "rhdh/rhdh-hub-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python3.14-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "fence-agents",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3.11-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "resource-agents",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "fence-agents",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.11-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.14-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/python-311",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/python-312",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/python-312-minimal",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/python-39",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/rhel-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ubi9/python-311",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ubi9/python-312",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ubi9/python-312-minimal",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ubi9/python-39",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-built-in-detector-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-nlp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-tgis-serving-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-guardrails-detector-huggingface-runtime-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kf-notebook-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llm-d-inference-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-notebook-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ta-lmes-job-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda121-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda124-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda128-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda128-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-service-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/rhai-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-olm-catalogd-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ztp-site-generate-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/foreman-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-frontend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-host-inventory-frontend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-host-inventory-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-insights-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-puptoo-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vmaas-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vulnerability-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vulnerability-frontend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-yuptoo-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Fix deferred",
        "package_name": "rhtas/model-transparency-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Fix deferred",
        "package_name": "rhtas/segment-reporting-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Fix deferred",
        "package_name": "stf/service-telemetry-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Fix deferred",
        "package_name": "stf/smart-gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-25645\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-25645\nhttps://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7\nhttps://github.com/psf/requests/releases/tag/v2.33.0\nhttps://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"
    ],
    "name": "CVE-2026-25645",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-02-10T17:04:38Z",
    "bugzilla": {
      "description": "libpng: LIBPNG has a heap buffer overflow in png_set_quantize",
      "id": "2438542",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2438542"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.",
      "A heap based buffer overflow flaw has been discovered in LibPNG. Prior to version 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3551",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "libpng-2:1.6.40-8.el10_1.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-03T00:00:00Z",
        "advisory": "RHSA-2026:3577",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libpng-2:1.6.40-8.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4756",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libpng-2:1.5.13-8.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7032",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libpng12-0:1.2.50-10.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6439",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libpng15-0:1.5.30-8.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6445",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libpng12-0:1.2.57-6.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-11T00:00:00Z",
        "advisory": "RHSA-2026:4306",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "mingw-libpng-0:1.6.34-2.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4728",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "libpng-2:1.6.34-10.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6466",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "libpng15-0:1.5.30-7.el8_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7035",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "libpng12-0:1.2.57-5.el8_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4732",
        "cpe": "cpe:/o:redhat:rhel_aus:8.2",
        "package": "libpng-2:1.6.34-8.el8_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6467",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libpng15-0:1.5.30-7.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7036",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libpng12-0:1.2.57-5.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4731",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "libpng-2:1.6.34-8.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6467",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libpng15-0:1.5.30-7.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7036",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libpng12-0:1.2.57-5.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4731",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "libpng-2:1.6.34-8.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6469",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libpng15-0:1.5.30-7.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7033",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libpng12-0:1.2.57-5.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4730",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "libpng-2:1.6.34-8.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6469",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "libpng15-0:1.5.30-7.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7033",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "libpng12-0:1.2.57-5.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4730",
        "cpe": "cpe:/o:redhat:rhel_tus:8.6",
        "package": "libpng-2:1.6.34-8.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6469",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "libpng15-0:1.5.30-7.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7033",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "libpng12-0:1.2.57-5.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4730",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.6",
        "package": "libpng-2:1.6.34-8.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6468",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libpng15-0:1.5.30-7.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7034",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libpng12-0:1.2.57-5.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4729",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "libpng-2:1.6.34-8.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6468",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libpng15-0:1.5.30-7.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7034",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libpng12-0:1.2.57-5.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4729",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "libpng-2:1.6.34-8.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-23T00:00:00Z",
        "advisory": "RHSA-2026:3031",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libpng15-0:1.5.30-14.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3405",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libpng-2:1.6.37-12.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-02-26T00:00:00Z",
        "advisory": "RHSA-2026:3405",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libpng-2:1.6.37-12.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-02T00:00:00Z",
        "advisory": "RHSA-2026:3573",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "libpng-2:1.6.37-12.el9_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4222",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "libpng15-0:1.5.30-14.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-03T00:00:00Z",
        "advisory": "RHSA-2026:3575",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libpng-2:1.6.37-12.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-03-10T00:00:00Z",
        "advisory": "RHSA-2026:4221",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libpng15-0:1.5.30-14.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-03T00:00:00Z",
        "advisory": "RHSA-2026:3574",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "libpng-2:1.6.37-12.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3969",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "libpng15-0:1.5.30-14.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-03T00:00:00Z",
        "advisory": "RHSA-2026:3576",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libpng-2:1.6.37-12.el9_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-09T00:00:00Z",
        "advisory": "RHSA-2026:3968",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libpng15-0:1.5.30-14.el9_6.1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-08T00:00:00Z",
        "advisory": "RHSA-2026:12274",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202604281506-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7239",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202604080111-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:15087",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202605060243-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14773",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202605060220-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10097",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202604211449-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17596",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202605112123-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6553",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202603261158-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7243",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202604080618-0"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8746",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1775680192"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8747",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1775680262"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8748",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1775749857"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5606",
        "cpe": "cpe:/a:redhat:ceph_storage:8::el9",
        "package": "rhceph/rhceph-8-rhel9:1774002867"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4501",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1773273070"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6732",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libpng-main-1.6.56-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Not affected",
        "package_name": "java-11-openjdk",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Not affected",
        "package_name": "java-11-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Not affected",
        "package_name": "java-17-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 1.8",
        "fix_state": "Not affected",
        "package_name": "java-1.8.0-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:1.8"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Not affected",
        "package_name": "java-21-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 25",
        "fix_state": "Not affected",
        "package_name": "java-25-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:25"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "java-25-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "libpng",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "java-1.8.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "java-1.8.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "java-25-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-25646\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-25646\nhttp://www.openwall.com/lists/oss-security/2026/02/09/7\nhttps://github.com/pnggroup/libpng/commit/01d03b8453eb30ade759cd45c707e5a1c7277d88\nhttps://github.com/pnggroup/libpng/security/advisories/GHSA-g8hp-mq4h-rqm3"
    ],
    "name": "CVE-2026-25646",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-03-03T14:28:37Z",
    "bugzilla": {
      "description": "django: Django: Incorrect file permissions due to race condition",
      "id": "2444111",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444111"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-367",
    "details": [
      "An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29.\nRace condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary `umask` change affects other threads in multi-threaded environments.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Tarek Nakkouch for reporting this issue.",
      "A flaw was found in Django. A race condition in the file-system storage and file-based cache backends allows an attacker to create file system objects with incorrect permissions. This vulnerability arises from concurrent requests in multi-threaded environments, where a temporary umask change in one thread can affect others. The consequence is potential unauthorized access or information disclosure due to misconfigured file permissions."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-25674\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-25674\nhttps://docs.djangoproject.com/en/dev/releases/security/\nhttps://groups.google.com/g/django-announce\nhttps://www.djangoproject.com/weblog/2026/mar/03/security-releases/"
    ],
    "name": "CVE-2026-25674",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-06T21:28:14Z",
    "bugzilla": {
      "description": "net/url: Incorrect parsing of IPv6 host literals in net/url",
      "id": "2445356",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1286",
    "details": [
      "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.",
      "The Go standard library function net/url.Parse insufficiently validated the host/authority component and accepted some invalid URLs by effectively treating garbage before an IP-literal as ignorable. The function should have rejected this as invalid."
    ],
    "affected_release": [
      {
        "product_name": "Cryostat 4 on RHEL 9",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6341",
        "cpe": "cpe:/a:redhat:cryostat:4::el9",
        "package": "cryostat/cryostat-storage-rhel9:4.1.1-6"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13512",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "automation-gateway-proxy-0:2.5.10-5.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13512",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "receptor-0:1.6.4-2.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13512",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "automation-gateway-proxy-0:2.6.14-2.el9"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13512",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "receptor-0:1.6.4-2.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13508",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el10",
        "package": "receptor-0:1.6.4-3.el10ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13508",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "automation-gateway-proxy-0:2.6.14-2.el9"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13508",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "receptor-0:1.6.4-2.el9ap"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10169",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "rhc-worker-playbook-0:0.2.3-4.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11412",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "yggdrasil-worker-package-manager-0:0.2.3-5.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11413",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "yggdrasil-0:0.4.8-4.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13642",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "image-builder-0:31-5.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13643",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "osbuild-composer-0:149-6.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5941",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "golang-0:1.25.8-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6344",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "grafana-0:10.2.6-23.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6388",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "grafana-pcp-0:5.3.0-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7005",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "git-lfs-0:3.6.1-8.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7669",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "rhc-1:0.3.4-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:7992",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "golang-github-openprinting-ipp-usb-0:0.9.27-5.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8840",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "go-rpm-macros-0:3.6.0-8.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8842",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "delve-0:1.25.2-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19017",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "podman-7:5.8.2-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19022",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "golang-0:1.26.2-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19026",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "grafana-pcp-0:5.3.0-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19027",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "grafana-0:10.2.6-25.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19031",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "skopeo-2:1.22.2-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19032",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "buildah-2:1.43.1-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19049",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "golang-github-openprinting-ipp-usb-0:0.9.27-6.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19055",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "rhc-1:0.3.8-3.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19126",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "yggdrasil-0:0.4.9-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19128",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "yggdrasil-worker-package-manager-0:0.2.3-6.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19132",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "rhc-worker-playbook-0:0.2.7-3.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19133",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "git-lfs-0:3.7.1-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19135",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "opentelemetry-collector-0:0.144.0-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22450",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "osbuild-composer-0:165.1-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22937",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "image-builder-0:52.1-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24386",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "podman-7:5.8.2-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29035",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "skopeo-2:1.22.2-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29195",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "buildah-2:1.43.1-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10133",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "golang-github-openprinting-ipp-usb-0:0.9.27-3.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10701",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "yggdrasil-worker-package-manager-0:0.2.3-5.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10929",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "rhc-worker-playbook-0:0.2.3-4.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11375",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "yggdrasil-0:0.4.7-3.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14868",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "buildah-2:1.39.8-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16696",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "skopeo-2:1.18.1-3.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17040",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "podman-6:5.4.0-15.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17084",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gvisor-tap-vsock-6:0.8.5-2.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19719",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "opentelemetry-collector-0:0.144.0-2.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19750",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "osbuild-composer-0:134.1-7.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5943",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "golang-0:1.25.8-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7328",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "rhc-1:0.3.2-3.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8314",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "delve-0:1.25.2-3.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8849",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "grafana-0:10.2.6-22.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8856",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "go-rpm-macros-0:3.6.0-6.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8931",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "grafana-pcp-0:5.2.2-5.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9435",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "git-lfs-0:3.6.1-2.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54191",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "rhc-worker-script-0:0.11-1.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8855",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "rhc-1:0.2.4-5.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16875",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "git-lfs-0:3.4.1-10.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33722",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "container-tools:rhel8-8100020260520103055.afee755d"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:6949",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "go-toolset:rhel8-8100020260402232122.a3795dee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7009",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "grafana-pcp-0:5.1.1-13.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7011",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "grafana-0:9.2.10-29.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7674",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "rhc-1:0.2.5-5.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8456",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "osbuild-composer-0:101.4-5.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7878",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "go-toolset:rhel8-8020020260408140623.02f7cb7a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8853",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "grafana-0:6.3.6-11.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20581",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "git-lfs-0:2.13.3-3.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52390",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "osbuild-composer-0:28.7-6.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7879",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "go-toolset:rhel8-8040020260408080443.5081a262"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8434",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "rhc-1:0.2.0-6.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9043",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "grafana-0:7.3.6-13.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9094",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "grafana-pcp-0:3.0.2-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20581",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "git-lfs-0:2.13.3-3.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52390",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "osbuild-composer-0:28.7-6.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7879",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "go-toolset:rhel8-8040020260408080443.5081a262"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8434",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "rhc-1:0.2.0-6.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9043",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "grafana-0:7.3.6-13.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9094",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "grafana-pcp-0:3.0.2-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19634",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "container-tools:rhel8-8060020260515174849.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20582",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "git-lfs-0:2.13.3-3.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51288",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "container-tools:rhel8-8060020260803064027.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52391",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "osbuild-composer-0:46.3-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7876",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "go-toolset:rhel8-8060020260409063558.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8851",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "rhc-1:0.2.1-14.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8860",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "grafana-0:7.5.11-10.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9093",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "grafana-pcp-0:3.2.0-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51288",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "container-tools:rhel8-8060020260803064027.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52391",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "osbuild-composer-0:46.3-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19634",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "container-tools:rhel8-8060020260515174849.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20582",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "git-lfs-0:2.13.3-3.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7876",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "go-toolset:rhel8-8060020260409063558.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8851",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "rhc-1:0.2.1-14.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8860",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "grafana-0:7.5.11-10.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9093",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "grafana-pcp-0:3.2.0-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19634",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "container-tools:rhel8-8060020260515174849.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20582",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "git-lfs-0:2.13.3-3.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7876",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "go-toolset:rhel8-8060020260409063558.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8851",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "rhc-1:0.2.1-14.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8860",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "grafana-0:7.5.11-10.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9093",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "grafana-pcp-0:3.2.0-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20584",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "git-lfs-0:3.2.0-2.el8_8.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49944",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "container-tools:rhel8-8080020260721142025.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52389",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "osbuild-composer-0:75-9.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7877",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "go-toolset:rhel8-8080020260331223648.6b4b45d8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8877",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "grafana-0:7.5.15-10.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8878",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "grafana-pcp-0:3.2.0-6.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9695",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "rhc-1:0.2.2-1.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20584",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "git-lfs-0:3.2.0-2.el8_8.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49944",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "container-tools:rhel8-8080020260721142025.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52389",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "osbuild-composer-0:75-9.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7877",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "go-toolset:rhel8-8080020260331223648.6b4b45d8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8877",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "grafana-0:7.5.15-10.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8878",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "grafana-pcp-0:3.2.0-6.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9695",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "rhc-1:0.2.2-1.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13671",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "image-builder-0:31-4.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19181",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "golang-0:1.26.2-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19184",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "grafana-pcp-0:5.1.1-14.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19185",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "grafana-0:10.2.6-21.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19207",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "rhc-1:0.2.7-5.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19350",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "git-lfs-0:3.7.1-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19353",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "opentelemetry-collector-0:0.144.0-2.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22714",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "osbuild-composer-0:165.1-2.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23228",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "image-builder-0:52.1-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26445",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "podman-6:5.8.2-2.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29455",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "buildah-2:1.43.1-2.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29702",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "runc-4:1.4.2-2.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29703",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "containernetworking-plugins-1:1.9.0-3.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36317",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "skopeo-2:1.22.2-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5942",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "golang-0:1.25.8-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6382",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "grafana-0:10.2.6-19.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6383",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "grafana-pcp-0:5.1.1-13.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7259",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "git-lfs-0:3.6.1-8.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7315",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "rhc-1:0.2.7-3.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8841",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "go-rpm-macros-0:3.6.0-14.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9044",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "osbuild-composer-0:149-5.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16102",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "buildah-1:1.26.11-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7883",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "golang-0:1.17.13-11.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8852",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "rhc-1:0.2.1-13.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8881",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "grafana-0:7.5.11-14.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8949",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "grafana-pcp-0:3.2.0-6.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9436",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "git-lfs-0:2.13.3-5.el9_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25248",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "podman-2:4.4.1-22.el9_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25250",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "skopeo-2:1.11.4-0.1.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25251",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "containernetworking-plugins-1:1.2.0-3.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25252",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "buildah-1:1.29.7-1.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25253",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "runc-4:1.2.9-1.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:48036",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "osbuild-composer-0:76.1-6.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7833",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "golang-0:1.19.13-24.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8322",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "rhc-1:0.2.2-1.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8879",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "grafana-0:9.0.9-11.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9090",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "grafana-pcp-0:5.1.1-5.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9434",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "git-lfs-0:3.2.0-2.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10712",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "git-lfs-0:3.4.1-4.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12028",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "podman-4:4.9.4-20.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12029",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "skopeo-2:1.14.5-2.el9_4.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12030",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "buildah-2:1.33.13-3.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12031",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "runc-4:1.2.9-1.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12032",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "containernetworking-plugins-1:1.4.0-6.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12033",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gvisor-tap-vsock-6:0.7.3-5.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19721",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "opentelemetry-collector-0:0.144.0-2.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7834",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "golang-0:1.21.13-15.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8324",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "rhc-1:0.2.4-7.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8882",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "grafana-pcp-0:5.1.1-7.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8930",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "grafana-0:9.2.10-26.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22733",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "osbuild-composer-0:101.3-4.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11749",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "buildah-2:1.39.6-2.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17287",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "podman-5:5.4.0-20.el9_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19475",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "osbuild-composer-0:132.2-6.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19720",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "opentelemetry-collector-0:0.144.0-2.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5944",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "golang-0:1.25.8-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7665",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "rhc-1:0.2.7-1.el9_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8845",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "grafana-pcp-0:5.1.1-13.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8847",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "grafana-0:10.2.6-19.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8848",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "go-rpm-macros-0:3.6.0-13.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9097",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "runc-4:1.2.9-3.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9098",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "skopeo-2:1.18.1-5.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9108",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gvisor-tap-vsock-6:0.8.5-2.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9109",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "containernetworking-plugins-1:1.6.2-3.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9439",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "git-lfs-0:3.6.1-2.el9_6.3"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26527",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "containernetworking-plugins-1:1.4.0-6.rhaos4.12.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26527",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "skopeo-2:1.9.4-8.rhaos4.12.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26541",
        "cpe": "cpe:/a:redhat:openshift:4.13::el8",
        "package": "containernetworking-plugins-1:1.4.0-7.rhaos4.13.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26541",
        "cpe": "cpe:/a:redhat:openshift:4.13::el8",
        "package": "podman-3:4.4.1-19.rhaos4.13.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26541",
        "cpe": "cpe:/a:redhat:openshift:4.13::el8",
        "package": "skopeo-2:1.11.3-6.rhaos4.13.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28886",
        "cpe": "cpe:/a:redhat:openshift:4.14::el8",
        "package": "containernetworking-plugins-1:1.4.0-6.rhaos4.14.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28886",
        "cpe": "cpe:/a:redhat:openshift:4.14::el8",
        "package": "podman-3:4.4.1-25.rhaos4.14.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:28961",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "containernetworking-plugins-1:1.4.0-6.rhaos4.15.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:28961",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "ose-aws-ecr-image-credential-provider-0:4.15.0-202606040938.p2.gfd77d92.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:28961",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "ose-azure-acr-image-credential-provider-0:4.15.0-202606040938.p2.g0d799a2.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:28961",
        "cpe": "cpe:/a:redhat:openshift:4.15::el8",
        "package": "ose-gcp-gcr-image-credential-provider-0:4.15.0-202606040938.p2.gfc50272.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-06-18T00:00:00Z",
        "advisory": "RHSA-2026:25043",
        "cpe": "cpe:/a:redhat:openshift:4.16::el8",
        "package": "ose-aws-ecr-image-credential-provider-0:4.16.0-202606031028.p2.ga53e9de.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-06-18T00:00:00Z",
        "advisory": "RHSA-2026:25043",
        "cpe": "cpe:/a:redhat:openshift:4.16::el8",
        "package": "ose-azure-acr-image-credential-provider-0:4.16.0-202606031028.p2.ge5bac33.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-06-18T00:00:00Z",
        "advisory": "RHSA-2026:25043",
        "cpe": "cpe:/a:redhat:openshift:4.16::el8",
        "package": "ose-gcp-gcr-image-credential-provider-0:4.16.0-202606031028.p2.g26b43df.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34097",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "containernetworking-plugins-1:1.4.0-9.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34097",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "ose-aws-ecr-image-credential-provider-0:4.17.0-202606022046.p2.g144bace.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34097",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "ose-azure-acr-image-credential-provider-0:4.17.0-202606171749.p2.g5bcfbfd.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34097",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "ose-gcp-gcr-image-credential-provider-0:4.17.0-202606022046.p2.g8ce997d.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34097",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "podman-5:5.2.2-19.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34097",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "runc-4:1.2.9-5.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34097",
        "cpe": "cpe:/a:redhat:openshift:4.17::el8",
        "package": "skopeo-2:1.16.1-6.rhaos4.17.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21655",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "containernetworking-plugins-1:1.4.0-9.rhaos4.18.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21655",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "podman-5:5.2.2-12.rhaos4.18.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21655",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "runc-4:1.2.9-6.rhaos4.18.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21655",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "skopeo-2:1.16.1-5.rhaos4.18.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25180",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "ose-aws-ecr-image-credential-provider-0:4.18.0-202606021914.p2.gc395190.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25180",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "ose-azure-acr-image-credential-provider-0:4.18.0-202606021914.p2.g9c24d76.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25180",
        "cpe": "cpe:/a:redhat:openshift:4.18::el8",
        "package": "ose-gcp-gcr-image-credential-provider-0:4.18.0-202606021914.p2.g6ea2356.assembly.stream.el8"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54757",
        "cpe": "cpe:/a:redhat:openstack:16.2::el8",
        "package": "collectd-sensubility-0:0.2.1-1.1.el8ost"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54757",
        "cpe": "cpe:/a:redhat:openstack:16.2::el8",
        "package": "etcd-0:3.3.23-22.el8ost"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1 for RHEL 9",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:28047",
        "cpe": "cpe:/a:redhat:openstack:17.1::el9",
        "package": "etcd-0:3.4.26-9.5.el9ost"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18.0",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39810",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "golang-github-openstack-k8s-operators-os-diff-0:0.1.1-18.0.20260602234716.a95ae05.el9ost"
      },
      {
        "product_name": "Red Hat Satellite 6.16 for RHEL 8",
        "release_date": "2026-06-18T00:00:00Z",
        "advisory": "RHSA-2026:27076",
        "cpe": "cpe:/a:redhat:satellite:6.16::el8",
        "package": "yggdrasil-worker-forwarder-0:0.0.3-5.el8sat"
      },
      {
        "product_name": "Red Hat Satellite 6.16 for RHEL 9",
        "release_date": "2026-06-18T00:00:00Z",
        "advisory": "RHSA-2026:27076",
        "cpe": "cpe:/a:redhat:satellite:6.16::el9",
        "package": "yggdrasil-worker-forwarder-0:0.0.3-5.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.17 for RHEL 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42150",
        "cpe": "cpe:/a:redhat:satellite:6.17::el9",
        "package": "yggdrasil-worker-forwarder-0:0.0.4-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.18 for RHEL 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42151",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "yggdrasil-worker-forwarder-0:0.0.4-1.el9sat"
      },
      {
        "product_name": "Red Hat Satellite 6.19 for RHEL 9",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34365",
        "cpe": "cpe:/a:redhat:satellite:6.19::el9",
        "package": "yggdrasil-worker-forwarder-0:0.0.3-5.el9sat"
      },
      {
        "product_name": "RHEM 1.0 for RHEL 9",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36796",
        "cpe": "cpe:/a:redhat:edge_manager:1.0::el9",
        "package": "flightctl-0:1.0.3-1.el9em"
      },
      {
        "product_name": "RHEM 1.1 for RHEL 10",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:41019",
        "cpe": "cpe:/a:redhat:edge_manager:1.1::el10",
        "package": "flightctl-0:1.1.3-1.el10em"
      },
      {
        "product_name": "RHEM 1.1 for RHEL 9",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:41019",
        "cpe": "cpe:/a:redhat:edge_manager:1.1::el9",
        "package": "flightctl-0:1.1.3-1.el9em"
      },
      {
        "product_name": "Compliance Operator 1",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8433",
        "cpe": "cpe:/a:redhat:openshift_compliance_operator:1::el9",
        "package": "compliance/openshift-compliance-operator-bundle:1776237332"
      },
      {
        "product_name": "Custom Metric Autoscaler 2.19",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26636",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2.19::el9",
        "package": "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9:1780101239"
      },
      {
        "product_name": "DevWorkspace Operator 0.4",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9872",
        "cpe": "cpe:/a:redhat:devworkspace:0.40::el9",
        "package": "devworkspace/devworkspace-rhel9-operator:1776457293"
      },
      {
        "product_name": "File Integrity Operator 1",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22627",
        "cpe": "cpe:/a:redhat:openshift_file_integrity_operator:1::el9",
        "package": "compliance/openshift-file-integrity-rhel8-operator:1780389566"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.0",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26585",
        "cpe": "cpe:/a:redhat:logging:6.0::el9",
        "package": "openshift-logging/eventrouter-rhel9:1781192891"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.2",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11800",
        "cpe": "cpe:/a:redhat:logging:6.2::el9",
        "package": "openshift-logging/eventrouter-rhel9:1776800087"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift 6.4",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22862",
        "cpe": "cpe:/a:redhat:logging:6.4::el9",
        "package": "openshift-logging/eventrouter-rhel9:1780051640"
      },
      {
        "product_name": "mirror registry for Red Hat OpenShift 2.0",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28441",
        "cpe": "cpe:/a:redhat:mirror_registry:2.0::el8",
        "package": "openshift/mirror-registry-rhel8:1782177012"
      },
      {
        "product_name": "Multicluster Global Hub 1.3.4",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22423",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.3::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1779210675"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21769",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1779828691"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5110",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1773650627"
      },
      {
        "product_name": "Network Observability (NETOBSERV) 1.11.1",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16874",
        "cpe": "cpe:/a:redhat:network_observ_optr:1.11::el9",
        "package": "network-observability/network-observability-cli-rhel9:1778508501"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29854",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-velero-rhel9:1779809598"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26568",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-velero-rhel9:1779808027"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25127",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/subctl-rhel9:1780238563"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8151",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/subctl-rhel9:1774085848"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11217",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1777307791"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13791",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1777986630"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13791",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-rhel8-operator:1777986630"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13791",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-roxctl-rhel8:1777986630"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13791",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-scanner-v4-rhel8:1777986630"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36319",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-scanner-rhel8:1782891812"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36319",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-scanner-slim-rhel8:1782891812"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.10",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13829",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.10::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1777976489"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.10",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13829",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.10::el8",
        "package": "advanced-cluster-security/rhacs-rhel8-operator:1777976489"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.10",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13829",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.10::el8",
        "package": "advanced-cluster-security/rhacs-roxctl-rhel8:1777976489"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.10",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13829",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.10::el8",
        "package": "advanced-cluster-security/rhacs-scanner-v4-rhel8:1777976489"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20889",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.10::el8",
        "package": "advanced-cluster-security/rhacs-scanner-rhel8:1778755463"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20889",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.10::el8",
        "package": "advanced-cluster-security/rhacs-scanner-slim-rhel8:1778755463"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/receptor-rhel9:1777391542"
      },
      {
        "product_name": "Red Hat Developer Hub 1.8",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9742",
        "cpe": "cpe:/a:redhat:rhdh:1.8::el9",
        "package": "rhdh/rhdh-rhel9-operator:1776783947"
      },
      {
        "product_name": "Red Hat Developer Hub 1.9",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6802",
        "cpe": "cpe:/a:redhat:rhdh:1.9::el9",
        "package": "rhdh/rhdh-rhel9-operator:1775140369"
      },
      {
        "product_name": "Red Hat Edge Manager 1.0",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36651",
        "cpe": "cpe:/a:redhat:edge_manager:1.0::el9",
        "package": "rhem/flightctl-ui-rhel9:1783502438"
      },
      {
        "product_name": "Red Hat Edge Manager 1.1",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40945",
        "cpe": "cpe:/a:redhat:edge_manager:1.1::el10",
        "package": "rhem/flightctl-ui-rhel10:1784194574"
      },
      {
        "product_name": "Red Hat Edge Manager 1.1",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:40118",
        "cpe": "cpe:/a:redhat:edge_manager:1.1::el9",
        "package": "rhem/flightctl-ui-rhel9:1784127736"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10140",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-aws-cuda-rhel9:1776871984"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10140",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-azure-cuda-rhel9:1776871985"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10140",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-azure-rocm-rhel9:1776872005"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10140",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-cuda-rhel9:1776773390"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10140",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-gcp-cuda-rhel9:1776871987"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10140",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-rocm-rhel9:1776773505"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10141",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/disk-image-cuda-rhel9:1776938871"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7291",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-26-main-1.26.2-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7385",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-25-main-1.25.9-1.hum1"
      },
      {
        "product_name": "Red Hat Lightspeed (formerly Insights) for Runtimes 1.0",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9052",
        "cpe": "cpe:/a:redhat:lightspeed_for_runtimes:1.0::el9",
        "package": "rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator:1.0.2-1776288486"
      },
      {
        "product_name": "Red Hat Migration Toolkit 1.8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41928",
        "cpe": "cpe:/a:redhat:rhmt:1.8::el8",
        "package": "rhmtc/openshift-migration-registry-rhel8:1783914276"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22347",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1779838819"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23345",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1780320809"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-rhel9-operator:1776773362"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.6.4",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5549",
        "cpe": "cpe:/a:redhat:openshift_builds:1.6::el9",
        "package": "openshift-builds/openshift-builds-waiters-rhel9:1774334066"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.7.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10158",
        "cpe": "cpe:/a:redhat:openshift_builds:1.7::el9",
        "package": "openshift-builds/openshift-builds-waiters-rhel9:1776846936"
      },
      {
        "product_name": "Red Hat OpenShift Builds 1.7.3",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11331",
        "cpe": "cpe:/a:redhat:openshift_builds:1.7::el9",
        "package": "openshift-builds/openshift-builds-waiters-rhel9:1776846936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1777002694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/egress-router-cni-rhel8:1777001625"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1777001562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/network-tools-rhel8:1777002936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1777042122"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1777001567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1777002279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1777002206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel8:1777001821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1777002716"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1777001811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1777001595"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1777001647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1777001622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1777001637"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1777001993"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1777002058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1777001588"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1777002145"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1777001819"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1777001657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1777001578"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1777002721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1777001896"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1777001576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1777001621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1777001630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cli:1776999989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cli-artifacts:1777002317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cloud-credential-operator:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1777002062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1777001657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-autoscaler:1777001639"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1777001616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1777001722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-bootstrap:1777001579"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1777001660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1777001660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1777001584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-config-operator:1777001860"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1777001588"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-dns-operator:1777001846"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1777001876"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1777001943"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1777001611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1777001561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1777001575"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1777001571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1777002164"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-machine-approver:1777001580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1777001813"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-network-operator:1777001698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-node-tuning-operator:1777002719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1777001569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1777001603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1777001612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1777001775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-samples-operator:1777001570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-storage-operator:1777001574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-cluster-version-operator:1777001558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-configmap-reloader:1777001608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-console:1777002039"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-console-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1777001571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-coredns:1777001653"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1777001577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1777001777"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1777001621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1777001656"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1777001606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-attacher:1777001646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1777001646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-provisioner:1776999972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1776999972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-resizer:1776999948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1776999948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1776999951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1776999951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-livenessprobe:1776999947"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1776999947"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1776999949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1776999949"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1777001741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1777001741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1777001992"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-docker-builder:1777001736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-docker-registry:1777001681"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-etcd:1777001596"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1777001898"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1777002697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1777001692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1777001837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-hyperkube:1777304752"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-hypershift-rhel8:1777001784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1777001854"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1777001574"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1777001888"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1777001586"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1777001561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1777002168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1777001585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-installer:1777000374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-installer-artifacts:1777003222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1777001763"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1777001618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-proxy:1777001642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1776999981"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-state-metrics:1777001815"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1777001549"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1777001541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1777001647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1777001659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1777001636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1777001608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1777001598"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-machine-config-operator:1777002732"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-admission-controller:1777001535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-cni:1777001584"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1777001612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1777001628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1777001576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-must-gather:1777000645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1777002718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1777001624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-proxy:1777001606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1777002057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1777002697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1777002725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1777001617"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1777001581"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1777001775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1777001580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1777001618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openstack-machine-controllers:1777001573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1777001630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-marketplace:1777001593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-operator-registry:1777001671"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1777001649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovn-kubernetes:1777002178"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel8:1777001818"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-pod:1777304565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1777001521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1777001566"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1777001771"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1777042146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus:1777001745"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1777001893"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1777002709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1777002720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-operator:1777001592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1777001726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-prom-label-proxy:1777001535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-sdn-rhel8:1777001790"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-service-ca-operator:1777001589"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-telemeter:1777001614"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-tests:1777002345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-thanos-rhel8:1777001839"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1777001605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1777001655"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1777001573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1777001605"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1777001599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1777001823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1777001631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1777001640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12282",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1777001645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-08T00:00:00Z",
        "advisory": "RHSA-2026:14100",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-tests:1778173182"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21696",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-sdn-rhel8:1779344506"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1779864120"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/egress-router-cni-rhel8:1779864235"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1779864128"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/network-tools-rhel8:1779313037"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1779889676"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1779889641"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1778765353"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1778765274"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel8:1779889723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1779863997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1779864079"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1779864508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1779864192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1779889720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1779863999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1779889660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1779889680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1779863969"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1779864074"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1779863989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1779889642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1779863994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1779864633"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1779864005"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1779889629"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1779889720"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1779864603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1779863994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1779864132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1779864485"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cli:1779889704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cli-artifacts:1778765373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cloud-credential-operator:1779864236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1779889678"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1779864074"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-autoscaler:1779863413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1779864513"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1779864055"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-bootstrap:1779864189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1779864740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1779864740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1779864043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-config-operator:1779863993"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1779863952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1779864018"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-dns-operator:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1779863985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1779864123"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1779864006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1779863976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1779864264"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1779889616"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1779889647"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1779864436"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-machine-approver:1779864047"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1779864102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-network-operator:1779889634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1779890827"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1779864733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1779864442"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1779864212"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1779889609"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-samples-operator:1779863398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-storage-operator:1779864003"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-cluster-version-operator:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-configmap-reloader:1779863974"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-console:1779864415"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-console-operator:1779889659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-coredns:1779864040"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1779889631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1779864020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1779864063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1779863966"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1779863998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1779864441"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-attacher:1779871348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1779871348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-provisioner:1779864793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1779864793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-resizer:1779864022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1779864022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1779864025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1779864025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-livenessprobe:1779864161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1779864161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1779864052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1779864052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1779889611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1779889611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1779889636"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-docker-builder:1779863452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-docker-registry:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-etcd-rhel9:1779890788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1779864509"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1779864100"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1779889604"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1779863996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-hyperkube:1779864503"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-hypershift-rhel8:1779864639"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1779889658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1779864019"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1779889649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1779889642"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1779864104"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1779863998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1779864066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1779864162"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-installer:1779864501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-installer-artifacts:1778766542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1779890216"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1779864028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-proxy:1779889635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1779889644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-state-metrics:1779864165"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1779889585"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1779864651"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1779863394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1779864348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-operator:1779864206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1779864736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1779864245"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1779864151"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1779864229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-machine-config-operator:1779864726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-admission-controller:1779864390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-cni:1779864023"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1779889657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1779863412"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1779863416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-must-gather:1778765257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1779864053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1779864236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel8:1779889646"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1779864046"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1779864015"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-proxy:1779863392"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1779889638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1779889640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1779889694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1779863972"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1779863952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1779864222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1779889602"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1779863995"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1779889649"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-marketplace:1779864043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-operator-registry:1779864451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1779864238"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes:1779891613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1779891537"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1779891613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-pod:1779864280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1779863962"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1779864153"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1779864168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1779864213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus:1779863444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1779863390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1779864034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1779863389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-operator:1779864228"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1779864564"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-prom-label-proxy:1779863397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-sdn-rhel8:1778765374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-service-ca-operator:1779864304"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-telemeter:1779889631"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-tests:1779313164"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-thanos-rhel8:1779889664"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1779864199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1779864192"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1779864001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1779864199"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1779889665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1779889644"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1779864320"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1779889619"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21691",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1779889628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1777996897"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/egress-router-cni-rhel8:1777997332"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1777997462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/network-tools-rhel8:1778172521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/oc-mirror-plugin-rhel8:1777997277"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1777996424"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1777998220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1777997994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1777472634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1777996679"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1777472583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel8:1777995469"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:1777995698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1777995577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel8:1777995808"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel8:1777996402"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel8:1777995599"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel8:1777995887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8:1777995699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel8-operator:1777995687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel8:1777995600"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel8:1777995569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel8:1777995734"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel8:1777995625"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8:1777995883"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1777995596"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1777995524"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel8:1777995841"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel8:1777995603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1777996820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-machine-controllers:1777996330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-rhel8-operator:1777997707"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel8:1777997365"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cli:1777995604"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cli-artifacts:1777998025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cloud-credential-operator:1777996333"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-api-rhel8:1777996553"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-authentication-operator:1777995495"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-autoscaler:1777994910"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-autoscaler-operator:1777996723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel8:1777997379"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-bootstrap:1777995458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-capi-operator-container-rhel8:1777997008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-capi-rhel8-operator:1777997008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-operator-rhel8:1777996635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-config-operator:1777996776"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-operator-rhel8:1777996381"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator:1777995506"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-dns-operator:1777995455"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-etcd-rhel8-operator:1777996270"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-image-registry-operator:1777996851"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-ingress-operator:1777996687"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-operator:1777995760"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator:1777996782"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-operator:1777997020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-operator:1777997255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator:1777997210"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-machine-approver:1777995462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-monitoring-operator:1777996292"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-network-operator:1778112812"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-node-tuning-operator:1777994001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1777994001"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-olm-operator-rhel8:1777996262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-operator:1777997116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-operator:1777996254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel8:1777996661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel8:1777996509"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-samples-operator:1777994956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-storage-operator:1777997078"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-cluster-version-operator:1777997456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-configmap-reloader:1777996314"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-console:1777997704"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-console-operator:1777997124"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1777997840"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-coredns:1777997281"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8:1777996831"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1777995492"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel8:1777996366"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1777996486"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel8:1777997218"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel8:1777997375"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-attacher:1777995459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel8:1777995459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-provisioner:1777995632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1777995632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-resizer:1777995652"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1777995652"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-snapshotter:1777995784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel8:1777995784"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-livenessprobe:1777995463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1777995463"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1777995491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1777995491"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-controller:1777996342"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel8:1777996342"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel8:1777996315"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-docker-builder:1777995244"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-docker-registry:1777997725"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-etcd-rhel9:1776786823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel8:1777996755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel8:1777996622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1777996228"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel8:1777996220"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1777472765"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-hypershift-rhel8:1778036600"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel8:1777997038"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel8:1777995572"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel8:1777997296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1777995692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel8:1777995653"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel8:1777995573"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1777995620"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-insights-rhel8-operator:1777996408"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-installer:1777996107"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-installer-artifacts:1778000857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1777994224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter:1777996885"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-proxy:1777995592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1777995480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-state-metrics:1777996287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel8:1777996488"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel8:1777997010"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-kuryr-cni-rhel8:1777994887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-libvirt-machine-controllers:1777995962"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-operator:1777995710"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel8:1777995601"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel8:1777995701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel8:1777995520"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel8:1777996613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-machine-config-operator:1777997630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-admission-controller:1777997528"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-cni:1778170887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel8:1777997407"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1777995116"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1777995224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-must-gather:1777996785"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1777997235"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel8:1777995460"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel8:1777995466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel8:1777995484"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel8:1777996597"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-proxy:1777995007"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-oauth-server-rhel8:1777997297"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-catalogd-rhel8:1777997176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel8:1777997205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1777997362"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1777997248"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel8:1777995735"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel8:1777997139"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8:1777997025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1777995629"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel8:1777997265"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-lifecycle-manager:1777996400"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-marketplace:1777995482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-operator-registry:1777995486"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovirt-machine-controllers-rhel8:1777997306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes:1778171006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1777950765"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1778171006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-pod:1777997313"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1777995498"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel8:1777996700"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel8:1777996514"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel8:1777996741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus:1777995270"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1777994952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-config-reloader:1777996409"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1777994918"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-operator:1777996333"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel8:1777996709"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-prom-label-proxy:1777995205"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-sdn-rhel8:1777998130"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-service-ca-operator:1777997562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-telemeter:1777997512"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-tests:1777998461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-thanos-rhel8:1777996367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1777995461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel8:1777995788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel8:1777995630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel8:1777995475"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1777995461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel8:1777995788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel8:1777995476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel8:1777995464"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8:1777996582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:15091",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1777997544"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28893",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-sdn-rhel8:1781835508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/cloud-network-config-controller-rhel8:1777994657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/egress-router-cni-rhel8:1777994713"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/kube-metrics-server-rhel8:1777994576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel8:1777994721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/network-tools-rhel8:1777998170"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1777519481"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel8:1777994523"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel8:1777998000"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel8:1777997820"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1777478482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel8:1777994504"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1777478234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel9:1777474101"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-cloud-csi-driver-container-rhel9:1777474453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:1777994483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel9:1777474227"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1777478096"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1777474127"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1777474416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1777474148"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1777474264"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1777474194"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1777474161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1777474315"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1777474158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel8-operator:1777994816"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1777474287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel8:1777994712"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1777474440"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel8:1777994558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-installer-rhel8:1778004053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1777518447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1777518423"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1777518340"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cli:1777994701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cli-artifacts:1777997939"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cloud-credential-operator:1777994673"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1777519328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1777519214"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1777518746"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1777518033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1777518321"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1777519394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1777519372"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1777518060"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1777478520"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1777519262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1777518061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1777478138"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1777519268"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1777518531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1777518280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1777519397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1777478065"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1777518472"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1777518634"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1777518054"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1777518444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1777478122"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1777518753"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1778101510"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1777993307"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-olm-operator-rhel8:1777994508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1777518628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1777519168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-platform-operators-manager-rhel9:1777518056"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1777518330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1777519183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1777518052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1777518379"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1777478476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-console:1777994748"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-console-rhel9-operator:1777518836"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel8:1777994759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-coredns-rhel9:1777518907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel8-operator:1777994680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1777476627"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1777477028"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-operator-rhel8:1777994803"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1777518277"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1777478042"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1777478430"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-provisioner:1777994744"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel8:1777994744"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-resizer:1777994749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel8:1777994749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1777474331"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-livenessprobe:1777994942"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel8:1777994942"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-node-driver-registrar:1777994483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel8:1777994483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1777518734"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1777518257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-docker-builder:1777993865"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1777518560"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-etcd-rhel9:1776790621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1777476910"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1777477747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel8:1777994733"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1777477500"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1777519044"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-hypershift-rhel9:1777560403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1777519438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1777474125"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1777474278"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-operator-rhel8:1777994563"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1777474357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ibm-vpc-node-label-updater-rhel9:1777474345"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-image-customization-controller-rhel8:1777994558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1777518743"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer:1778003878"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer-altinfra-rhel8:1777995426"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-installer-artifacts:1778003967"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1777993546"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter-rhel9:1777478078"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1777519369"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-rbac-proxy:1777994806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1777518797"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1777518058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1777518288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1777993309"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1777474219"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1777474262"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1777477119"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1777518088"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1777519221"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-machine-config-operator:1777994925"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1777478301"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-cni:1777994726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1777519086"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel8:1777993775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel8:1777993779"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-must-gather:1777995829"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel8:1777994575"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1777519043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1777474308"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1777474367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1777518060"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1777518740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1777542478"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-catalogd-rhel8:1777994525"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel8:1777995008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-olm-rukpak-rhel8:1777994685"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1777518479"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1777518376"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1777519359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel8-operator:1777994467"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1777519284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1777519438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel8:1777994805"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1777545280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1777518048"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1777518565"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1777950961"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1777951025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-pod-rhel9:1777518607"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-operator-rhel8:1777994861"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1777476821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1777476388"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1777477330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus:1777993863"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-alertmanager:1777993798"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1777478113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-node-exporter:1777993796"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1777478254"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1777518755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-prom-label-proxy:1777993793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-sdn-rhel9:1777518582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1777478120"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-telemeter-rhel9:1777518059"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-tests:1777998234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-thanos-rhel8:1777994557"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8:1777994462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1777474367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1777474390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1777474189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-operator-rhel8:1777994462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1777474367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1777474311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1777474366"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ovirt-csi-driver-rhel8-operator:1777994505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14774",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1777478134"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1779262531"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1779257059"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1779251936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1779257911"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/egress-router-cni-rhel9:1779252559"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1779263513"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1779258057"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/network-tools-rhel9:1779269865"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1779252293"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1779255317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1779254514"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1779258263"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1779256917"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1779251346"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1779263613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-alibaba-cloud-controller-manager-rhel9:1779250446"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-alibaba-machine-controllers-rhel9:1779250072"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1779263764"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1779250003"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1779250170"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1779250061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1779249996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1779250416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1779250137"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1779250036"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1779250124"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1779250177"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1779250039"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1779250067"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1779251456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1779250071"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1779269423"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1779256787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1779262505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1779254840"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1779261668"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cli-rhel9:1779253413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1779250856"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1779261997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1779256730"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1779250701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1779251982"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1779252065"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1779251832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1779263420"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1779258183"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1779263384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1779259613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1779262272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1779252871"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1779252385"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1779258849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1779262399"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1779251986"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1779257509"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1779263748"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1779255692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1779258155"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1779263842"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1779251792"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1779250889"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1779258985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1779252665"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1779258986"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1779263511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1779256025"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1779259882"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1779253958"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1779259370"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1779263189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1779252337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-console-rhel9:1779258913"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-console-rhel9-operator:1779251959"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1779253897"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-coredns-rhel9:1779254114"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1779250591"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1779253593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1779253321"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1779258717"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9-operator:1779255989"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1779250132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1779262779"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1779251129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1779253452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1779252626"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1779250200"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1779251358"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1779251893"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1779254156"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1779249986"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1779261706"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-etcd-rhel9:1779258224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1779251758"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1779254105"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1779250532"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1779251295"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1779263073"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-hypershift-rhel9:1779260812"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1779256393"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1779250211"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1779250499"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1779250628"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1779250592"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1779250009"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1779261020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1779281061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1779281084"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-installer-rhel9:1779281052"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1779249229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-k8s-prometheus-adapter-rhel9:1779253448"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1779251778"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1779252619"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1779252959"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1779252723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1779258382"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1779251500"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1779250152"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1779250032"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1779250449"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1779258721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1779252859"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1779252062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1779262789"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1779263539"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1779257736"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1779250571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1779259043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1779254313"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-must-gather-rhel9:1779256131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1779261577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1779251811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1779250062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1779278543"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1779252089"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1779250609"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1779251536"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1779263779"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1779253467"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-olm-rukpak-rhel9:1779263844"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1779254455"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1779256815"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1779260915"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1779254907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1779252990"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1779250744"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1779253663"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1779263073"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1779260328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1779251927"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1779256134"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1779255831"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1779263069"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-pod-rhel9:1779250716"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1779251117"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1779253258"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1779251059"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1779251590"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1779255735"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1779262624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1779250747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1779251726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-rhel9:1779250180"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1779253852"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1779258763"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-sdn-rhel9:1779252050"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1779256002"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-telemeter-rhel9:1779251836"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-tests-rhel9:1779266539"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-thanos-rhel9:1779262189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-tools-rhel9:1779253265"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1779250064"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1779250066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1779249999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1779250085"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1779250064"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1779250066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1779250033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1779250030"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1779262700"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20088",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1779254541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1778712094"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1778710338"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1778711456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1778710367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/egress-router-cni-rhel9:1778709318"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/frr-rhel9:1778701092"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1778711399"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1778711660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/network-tools-rhel9:1778718976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1778711674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1778711701"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1778711791"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1778711754"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1778711558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1778712111"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1778711782"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1778709420"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1778707346"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1778707380"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1778706811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1778707968"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1778707697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1778707580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1778706759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1778708031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1778708041"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1778707987"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1778707251"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1778707728"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1778707699"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1778710129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1778718808"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1778711719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1778709794"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1778711768"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1778715516"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cli-rhel9:1778701275"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1778710063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1778711773"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1778710542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1778710806"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1778711741"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1778709640"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1778710891"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1778711802"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1778710438"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1778710279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1778709692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1778709724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1778710173"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1778711613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1778709691"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1778711680"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1778709871"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1778710213"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1778711635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1778711609"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1778710421"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1778712033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1778710716"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1778709729"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1778710367"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1778710661"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1778709393"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1778710617"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1778709403"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1778711783"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1778710126"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1778710517"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1778710545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1778710326"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-console-rhel9:1778718159"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-console-rhel9-operator:1778711749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1778710525"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-coredns-rhel9:1778710280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1778707878"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1778706645"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1778707862"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9:1778710445"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-rhel9-operator:1778709335"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-driver-shared-resource-webhook-rhel9:1778709792"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1778710349"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1778701149"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1778700996"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1778700848"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1778700853"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1778700834"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1778709405"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1778710562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1778710258"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1778710229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-etcd-rhel9:1778709845"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1778708017"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1778707997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1778707723"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1778708241"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1778711747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1778709689"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-hypershift-rhel9:1778710288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1778710227"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1778709545"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1778711793"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1778711557"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1778711683"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1778707299"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1778709453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1778711880"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1778710754"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-installer-rhel9:1778710373"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1778707494"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1778711543"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1778701099"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1778709982"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1778710673"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1778710837"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1778709447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1778707722"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1778707724"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1778707284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1778711757"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1778710857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1778711867"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1778718013"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1778711711"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1778711618"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1778709750"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1778710823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1778711608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1778710881"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-must-gather-rhel9:1778702552"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1778711621"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1778710845"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1778707466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1778707832"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1778710582"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1778709208"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1778709413"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1778711551"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1778710351"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1778710181"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1778711581"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1778710026"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1778711478"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1778709328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1778711721"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1778710093"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1778710263"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1778710541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1778709398"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1778709325"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1778710391"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1778710176"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-pod-rhel9:1778711650"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1778707884"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1778707466"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1778706638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1778707549"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1778711553"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1778709872"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1778709287"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1778709431"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-rhel9:1778710296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1778709906"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1778710862"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1778710475"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-telemeter-rhel9:1778711679"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-tests-rhel9:1778715654"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-thanos-rhel9:1778710497"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-tools-rhel9:1778701268"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1778707501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1778707849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1778707857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1778707857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1778707501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1778707849"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1778707482"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1778707873"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1778709987"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1778710215"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1779783306"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1779779659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/azure-service-rhel9-operator:1779787971"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1779786021"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1779787854"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/egress-router-cni-rhel9:1779787613"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/frr-rhel9:1779778465"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1779782389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1779787561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1779786555"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1779779058"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/network-tools-rhel9:1779794717"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1779780952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1779786977"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1778879426"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1779787425"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1779787449"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1779782716"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1779787048"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1779782011"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1779778918"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1779779017"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1779778894"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1779778955"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1779778926"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1779778988"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1779778973"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1779778938"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1779257774"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1779778937"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1779778879"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1779780313"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1779778898"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1779787251"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1779795067"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1779783654"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1779786507"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1779787304"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1779787392"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cli-rhel9:1779780731"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1779804386"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1779781266"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1779781173"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1779785029"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1779785958"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1779787692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1779787660"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1779873946"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1779782449"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1779781920"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1779781799"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1779787880"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1779780280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1779786975"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1779787317"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1779787755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1779787694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1779778919"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1779781142"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1779782692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1779787164"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1779781031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1779781940"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1779782866"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1779782622"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1779860114"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1779787336"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1779787477"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1779787713"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1779784577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1779784982"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1779784139"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1779786068"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1779780493"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9:1779875193"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-console-rhel9-operator:1779783956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1779786583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-coredns-rhel9:1779783064"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1779781222"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1779781289"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1779781299"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1779787474"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1779780830"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1779780578"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1779890000"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1779780257"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1779780819"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1779889988"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-snapshot-validation-webhook-rhel9:1779889982"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1779778738"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1779783272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-etcd-rhel9:1779785143"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1779779851"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1779780611"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1779780775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1779781122"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1779780662"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1779787959"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-hypershift-rhel9:1779804441"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1779786992"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1779779902"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1779779787"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1779780440"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1779780418"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1779778900"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1779786900"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-altinfra-rhel9:1779846267"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1779849795"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-installer-rhel9:1779849746"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1779777985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1779784029"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1779781229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1779783744"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1779787006"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1779780483"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1779781200"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1779778958"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1779778871"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1779780811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1779786461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1779782881"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1779846066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1779874891"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1779787214"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1779785509"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1779787632"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1779785533"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1779787252"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1779782423"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-must-gather-rhel9:1779781840"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1779786474"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1779787165"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1779778911"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1779778885"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1779787498"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1779785000"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1779787719"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1779784020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1779804423"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1779787506"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1779782284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1779780763"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1779780904"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1779784217"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1779783551"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1779783241"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1779785459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1779787191"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1779786541"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1779778945"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1779788053"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1779788112"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-pod-rhel9:1779786458"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1779780954"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1779781097"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1779780749"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1779779596"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1779787823"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1779787674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1779787129"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1779787158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9:1779780674"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1779784201"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1779787558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1779780497"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-telemeter-rhel9:1779787656"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tests-rhel9:1779788300"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-thanos-rhel9:1779787641"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-tools-rhel9:1779860157"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1779778916"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1779778894"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1779778977"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1779778935"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1779778916"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1779778894"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1779778925"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1779778933"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1779787747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21657",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1779787600"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1779249758"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1779256571"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1779258135"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-service-rhel9-operator:1779252024"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1779253570"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1779253488"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/egress-router-cni-rhel9:1779261865"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/frr-rhel9:1779250510"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1779260654"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1779259294"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1779250061"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1779251657"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/network-tools-rhel9:1779266318"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1779258799"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1779251627"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openstack-resource-controller-rhel9:1779253510"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1779255162"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1779256783"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1779250890"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1779254290"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1779251975"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1779251775"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1779250020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1779249958"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1779249856"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1779249810"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1779249815"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1779249921"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1779249920"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1779249904"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1779249882"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1779249888"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1779249816"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1779251421"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1779249867"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1779252547"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1779266535"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1779252705"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1779252653"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1779252404"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1779266125"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-rhel9:1779252397"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1779251451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1779250439"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1779261185"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1779258998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1779253447"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1779261971"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1779251452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1779253898"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1779260065"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1779254302"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1779250890"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1779253393"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1779253385"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1779256678"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1779251008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1779254529"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1779260460"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1779254974"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1779254092"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1779257951"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1779250104"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1779251288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1779256795"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1779251239"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1779252359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1779262020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1779261357"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1779256168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1779250971"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1779258265"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1779250658"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1779252171"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1779252684"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1779256324"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9:1779251663"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9-operator:1779258747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1779251264"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-coredns-rhel9:1779259229"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1779249755"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1779250594"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1779251714"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1779250043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1779249778"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1779249992"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1779250695"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1779250630"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1779250608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1779250566"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1779250763"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1779252907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-etcd-rhel9:1779252012"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1779251008"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1779250924"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1779250542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1779251624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1779259469"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1779254759"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hypershift-rhel9:1779251388"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1779252756"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1779249912"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1779250066"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1779250238"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1779249782"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1779249869"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1779254528"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1779266769"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-rhel9:1779269991"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1779281737"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1779257412"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1779250656"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1779252253"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1779251292"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1779249762"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1779256697"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1779249874"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1779249850"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1779249810"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1779250020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1779261172"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1779259948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1779249923"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1779261887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1779251145"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1779252360"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1779251274"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1779262154"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1779251391"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-must-gather-rhel9:1779256086"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1779251977"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1779260043"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1779249747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1779249698"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1779261667"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1779251997"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1779253952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1779257188"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1779249794"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1779257694"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1779251286"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1779252319"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1779249811"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1779251201"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1779249913"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1779252446"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1779251417"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1779257812"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1779250594"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1779251906"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1779259423"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1779253485"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-pod-rhel9:1779258884"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1779251684"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1779250348"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1779249727"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1779249713"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1779252959"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1779257956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1779251715"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1779252281"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9:1779253774"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1779256852"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1779261734"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1779262026"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-telemeter-rhel9:1779253452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tests-rhel9:1779266169"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-thanos-rhel9:1779253464"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tools-rhel9:1779249892"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1779249748"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1779249696"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1779249727"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1779249836"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1779249748"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1779249696"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1779249727"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1779249715"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1779262190"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1779251232"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1774637484"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1774651926"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1774634707"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/azure-service-rhel9-operator:1774636953"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1774634477"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1774652089"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/egress-router-cni-rhel9:1774636444"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/frr-rhel9:1774634887"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1774651915"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1774636718"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1774634925"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1774635244"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/network-tools-rhel9:1775010888"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1774635538"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1774634580"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/openstack-resource-controller-rhel9:1774635034"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1774637561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1774635280"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1774634537"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1774637264"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-ui-rhel9:1774977480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1774636390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1774634715"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1774634113"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1774634181"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1774634218"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1774634169"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1774634142"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1774634145"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1774634145"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1774634134"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1774634158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1774634105"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1774634092"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1774635144"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1774634095"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1774634505"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1775064538"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1774636495"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1775084215"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1774635311"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1774653285"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cli-rhel9:1774652339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1774858510"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1774634587"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1774634712"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1774637384"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1774636268"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1774637331"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1774637189"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1774652024"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1774651993"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1774634562"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1774637276"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1774634377"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1774636747"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1774635685"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1774651954"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1774635915"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1774634578"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1774635432"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1774634448"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1774635542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1774651948"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1774651930"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1774635740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1774652160"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1774634475"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1775006910"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1774634941"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1774637158"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1774637168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1774636352"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1774635460"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1774637478"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1774635955"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1774651903"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-console-rhel9:1775019921"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-console-rhel9-operator:1774637090"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1774637081"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-coredns-rhel9:1774636542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1774634022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1774634033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1774634735"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1774635418"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1774635853"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1774637297"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-snapshot-metadata-rhel9:1774637026"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1774634540"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1774635312"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1774636489"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1774634740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1774638071"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1774637076"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-etcd-rhel9:1774634425"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1774635826"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1774635957"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1774651943"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1775091051"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1774634583"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1774634692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-hypershift-rhel9:1774652288"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1774634737"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1774636002"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1774959132"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1774635855"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1774635044"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1774891095"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1774651955"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1775064607"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-installer-rhel9:1775064490"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1774891577"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1774635141"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1774637093"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1774636572"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1774637412"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1774635966"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1774636383"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1774634119"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1774634144"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1774636296"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1774636533"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1774636031"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1774758099"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1774652245"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1774634377"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1774636168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1774637394"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1774634819"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1774636962"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1774637173"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-must-gather-rhel9:1774653160"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1774651944"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1774635920"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1774634067"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1774634012"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1774636802"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1774651931"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1774635789"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1774635472"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1774634942"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1774636594"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1774634567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1774634040"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1775091049"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1774636977"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1774637981"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1774652195"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1774851768"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1774851740"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1774635881"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1774851746"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1774931807"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1774931944"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-pod-rhel9:1774635212"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1774652241"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1775054956"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1774634339"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1774634017"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1774637360"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1774635299"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1774634111"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1774635267"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-rhel9:1774946635"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1774637910"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1774634453"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1774636700"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-telemeter-rhel9:1774651939"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-tests-rhel9:1775010884"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-thanos-rhel9:1774637428"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-tools-rhel9:1775007032"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1774634037"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1774634011"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1774634033"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1774634054"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1774634037"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1774634011"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1774634045"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1774634020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1774636143"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1774651928"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:6564",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/volume-data-source-validator-rhel9:1774635068"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.27",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10175",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.27::el9",
        "package": "devspaces/udi-rhel9:1776789889"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9385",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/tempo-rhel9:1776435680"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11688",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/istio-cni-rhel8:1777374598"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11688",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/istio-rhel8-operator:1777320087"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11688",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/pilot-rhel8:1777319850"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11688",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/ratelimit-rhel8:1777319773"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8483",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/kiali-rhel8:1776191302"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11686",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el9",
        "package": "openshift-service-mesh/proxyv2-rhel9:1777375171"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8484",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/kiali-rhel9:1776151272"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9440",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1776181080"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9440",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1776181166"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9440",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1776240392"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.0",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9440",
        "cpe": "cpe:/a:redhat:service_mesh:3.0::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1776180733"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8490",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/kiali-rhel9:1776151270"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9448",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1776238635"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9448",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1776256858"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9448",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1776315466"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9448",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1776232570"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8491",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/kiali-rhel9:1776149682"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9453",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1776178280"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9453",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1776178059"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9453",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1776291540"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9453",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1776232405"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.3",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8493",
        "cpe": "cpe:/a:redhat:service_mesh:3.3::el9",
        "package": "openshift-service-mesh/kiali-rhel9:1776151277"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.3",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9461",
        "cpe": "cpe:/a:redhat:service_mesh:3.3::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1776233000"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.3",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9461",
        "cpe": "cpe:/a:redhat:service_mesh:3.3::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1776233016"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.3",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9461",
        "cpe": "cpe:/a:redhat:service_mesh:3.3::el9",
        "package": "openshift-service-mesh/istio-proxyv2-rhel9:1776293296"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.3",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9461",
        "cpe": "cpe:/a:redhat:service_mesh:3.3::el9",
        "package": "openshift-service-mesh/istio-rhel9-operator:1776419718"
      },
      {
        "product_name": "Red Hat OpenStack Services on OpenShift 18",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11747",
        "cpe": "cpe:/a:redhat:openstack:18.0::el9",
        "package": "rhoso-operators/sg-core-rhel9:1774974026"
      },
      {
        "product_name": "Red Hat Quay 3.1",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11916",
        "cpe": "cpe:/a:redhat:quay:3.10::el8",
        "package": "quay/quay-rhel8:1776736910"
      },
      {
        "product_name": "Red Hat Quay 3.12",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11856",
        "cpe": "cpe:/a:redhat:quay:3.12::el8",
        "package": "quay/quay-rhel8:1776752646"
      },
      {
        "product_name": "Red Hat Quay 3.12",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6720",
        "cpe": "cpe:/a:redhat:quay:3.12::el8",
        "package": "quay/quay-rhel8:1775253092"
      },
      {
        "product_name": "Red Hat Quay 3.14",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:21017",
        "cpe": "cpe:/a:redhat:quay:3.14::el8",
        "package": "quay/quay-rhel8:1779689392"
      },
      {
        "product_name": "Red Hat Quay 3.15",
        "release_date": "2026-06-09T00:00:00Z",
        "advisory": "RHSA-2026:24853",
        "cpe": "cpe:/a:redhat:quay:3.15::el8",
        "package": "quay/quay-rhel8:1780891395"
      },
      {
        "product_name": "Red Hat Quay 3.16",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19375",
        "cpe": "cpe:/a:redhat:quay:3.16::el9",
        "package": "quay/quay-rhel9:1779204086"
      },
      {
        "product_name": "Red Hat Quay 3.9",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:11996",
        "cpe": "cpe:/a:redhat:quay:3.9::el8",
        "package": "quay/quay-rhel8:1776782369"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14879",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/iop-vmaas-rhel9:1778082595"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10125",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/client-server-rhel9:1776339099"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1777459504"
      },
      {
        "product_name": "Red Hat Web Terminal 1.11",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10250",
        "cpe": "cpe:/a:redhat:webterminal:1.11::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1776966691"
      },
      {
        "product_name": "Red Hat Web Terminal 1.12",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10225",
        "cpe": "cpe:/a:redhat:webterminal:1.12::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1776959849"
      },
      {
        "product_name": "Red Hat Web Terminal 1.13",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8338",
        "cpe": "cpe:/a:redhat:webterminal:1.13::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1776197785"
      },
      {
        "product_name": "Red Hat Web Terminal 1.14",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8337",
        "cpe": "cpe:/a:redhat:webterminal:1.14::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1776199398"
      },
      {
        "product_name": "Red Hat Web Terminal 1.15",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8167",
        "cpe": "cpe:/a:redhat:webterminal:1.15::el9",
        "package": "web-terminal/web-terminal-exec-rhel9:1775672762"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14020",
        "cpe": "cpe:/a:redhat:stf:1.5::el9",
        "package": "stf/sg-core-rhel9:1777452570"
      }
    ],
    "package_state": [
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "rhai/assisted-installer-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/jetstack-cert-manager-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "build-of-trustee/trustee-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "openshift-sandboxed-containers/osc-monitor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Deployment Validation Operator",
        "fix_state": "Affected",
        "package_name": "dvo/deployment-validation-rhel8-operator",
        "cpe": "cpe:/a:redhat:deployment_validator_operator"
      },
      {
        "product_name": "ExternalDNS Operator",
        "fix_state": "Affected",
        "package_name": "edo/external-dns-rhel8",
        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
      },
      {
        "product_name": "ExternalDNS Operator",
        "fix_state": "Affected",
        "package_name": "edo/external-dns-rhel9",
        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Will not fix",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "Fence Agents Remediation Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/fence-agents-remediation-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_far:0"
      },
      {
        "product_name": "Gatekeeper 3",
        "fix_state": "Affected",
        "package_name": "gatekeeper/gatekeeper-rhel9-operator",
        "cpe": "cpe:/a:redhat:gatekeeper:3"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Will not fix",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Will not fix",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Affected",
        "package_name": "lvms4/lvms-rhel9-operator",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Not affected",
        "package_name": "lvms4/topolvm-rhel8",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Affected",
        "package_name": "lvms4/topolvm-rhel9",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/machine-deletion-remediation-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-cli-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "mirror registry for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift/mirror-registry-rhel8",
        "cpe": "cpe:/a:redhat:mirror_registry:1"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Under investigation",
        "package_name": "multicluster-engine/assisted-service-9-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/discovery-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/node-healthcheck-rhel8-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "helm",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines-client",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Not affected",
        "package_name": "kn-workflow-plugin",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-plugin-event-sender-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-clients",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "rh-osbs/openshift-golang-builder",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Power monitoring for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-power-monitoring/kepler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_power_monitoring"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp2/3scale-rhel7-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Affected",
        "package_name": "3scale-amp2/3scale-rhel9-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp26/3scale-operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp26/operator",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat AMQ Clients",
        "fix_state": "Not affected",
        "package_name": "python39-qpid-proton",
        "cpe": "cpe:/a:redhat:amq_clients:2023"
      },
      {
        "product_name": "Red Hat AMQ Clients",
        "fix_state": "Not affected",
        "package_name": "qpid-proton",
        "cpe": "cpe:/a:redhat:amq_clients:2023"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform/platform-operator-bundle",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "automation-gateway-proxy-openssl30",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "automation-gateway-proxy-openssl32",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3.11-galaxy-ng",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3.11-grpcio",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3.12-galaxy-ng",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3.12-grpcio",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3x-grpcio",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python-grpcio",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat build of Apache Camel - HawtIO 4",
        "fix_state": "Not affected",
        "package_name": "hawtio-operator-container",
        "cpe": "cpe:/a:redhat:apache_camel_hawtio:4"
      },
      {
        "product_name": "Red Hat Certification Program for Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "redhat-certification-preflight",
        "cpe": "cpe:/a:redhat:certifications:9"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Affected",
        "package_name": "rhcl-1/coredns-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Will not fix",
        "package_name": "butane",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "go-fdo-client",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "go-fdo-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "gvisor-tap-vsock",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Will not fix",
        "package_name": "ignition",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "rhel10/bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rsyslog",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "host-metering",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "rsyslog",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "weldr-client",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "butane",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "gvisor-tap-vsock",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "ignition",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "rhel9/bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rsyslog",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "weldr-client",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Cluster Manager CLI",
        "fix_state": "Affected",
        "package_name": "ocm-cli-clients/ocm-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_cluster_manager_cli:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "butane",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "conmon",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "conmon-rs",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "cri-o",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "cri-tools",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "golang-github-prometheus-promu",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "ignition",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "microshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/frr-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-sdn-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift-clients",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift-kuryr",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "rh-osbs/openshift-golang-builder",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Affected",
        "package_name": "odf4/cephcsi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Not affected",
        "package_name": "openshift4-wincw/windows-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/dex-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift on AWS",
        "fix_state": "Affected",
        "package_name": "rosa",
        "cpe": "cpe:/a:redhat:openshift_service_on_aws:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-api",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-api-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "kubevirt",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "rh-osbs/openshift-golang-builder",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "golang-github-infrawatch-apputils",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "golang-qpid-apache",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "qpid-proton",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/osp-director-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Affected",
        "package_name": "collectd-libpod-stats",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Affected",
        "package_name": "golang-github-infrawatch-apputils",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Affected",
        "package_name": "golang-qpid-apache",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "qpid-proton",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel9/osp-director-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-builder-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "satellite:el8/yggdrasil-worker-forwarder",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Service Interconnect 1",
        "fix_state": "Will not fix",
        "package_name": "qpid-proton",
        "cpe": "cpe:/a:redhat:service_interconnect:1"
      },
      {
        "product_name": "Red Hat Service Interconnect 1",
        "fix_state": "Not affected",
        "package_name": "skupper-cli",
        "cpe": "cpe:/a:redhat:service_interconnect:1"
      },
      {
        "product_name": "Red Hat Service Interconnect 2",
        "fix_state": "Will not fix",
        "package_name": "qpid-proton",
        "cpe": "cpe:/a:redhat:service_interconnect:2"
      },
      {
        "product_name": "Red Hat Service Interconnect 2",
        "fix_state": "Not affected",
        "package_name": "skupper-cli",
        "cpe": "cpe:/a:redhat:service_interconnect:2"
      },
      {
        "product_name": "Red Hat Service Interconnect 2",
        "fix_state": "Will not fix",
        "package_name": "skupper-router",
        "cpe": "cpe:/a:redhat:service_interconnect:2"
      },
      {
        "product_name": "Security Profiles Operator",
        "fix_state": "Affected",
        "package_name": "compliance/openshift-selinuxd-rhel8",
        "cpe": "cpe:/a:redhat:openshift_security_profiles_operator:1"
      },
      {
        "product_name": "streams for Apache Kafka 3",
        "fix_state": "Will not fix",
        "package_name": "golang-github-danielqsj-kafka_exporter",
        "cpe": "cpe:/a:redhat:amq_streams:3"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager",
        "fix_state": "Affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-25679\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-25679\nhttps://go.dev/cl/752180\nhttps://go.dev/issue/77578\nhttps://groups.google.com/g/golang-announce/c/EdhZqrQ98hk\nhttps://pkg.go.dev/vuln/GO-2026-4601"
    ],
    "name": "CVE-2026-25679",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-06T22:43:38Z",
    "bugzilla": {
      "description": "vim: Vim: Arbitrary code execution via 'helpfile' option processing",
      "id": "2437843",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2437843"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags, Vim copies the user-controlled 'helpfile' option value into a fixed-size heap buffer of MAXPATHL + 1 bytes (typically 4097 bytes) using an unsafe STRCPY() operation without any bounds checking. This issue has been patched in version 9.1.2132.",
      "A flaw was found in Vim, an open source, command line text editor. This heap buffer overflow vulnerability exists in the tag file resolution logic when processing the 'helpfile' option. A local user could exploit this by providing a specially crafted 'helpfile' option value, leading to a heap buffer overflow. This could result in arbitrary code execution or a denial of service."
    ],
    "statement": "This MODERATE impact vulnerability in Vim's tag file resolution logic allows a local attacker to achieve a out-of-bounds write. By providing a specially crafted `helpfile` option value a local user can trigger a heap buffer overflow, as consequence lead to memory corruption presenting a data integrity impact or leading the vim process to crash resulting in availability impact. Although being non-trivial and very complex, arbitrary code execution is not discarded as worst case scenario.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-17T00:00:00Z",
        "advisory": "RHSA-2026:4715",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "vim-2:9.1.083-6.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6502",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6617",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "vim-2:7.4.629-8.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4442",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-22.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-12T00:00:00Z",
        "advisory": "RHSA-2026:4442",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-22.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6730",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "vim-2:8.0.1763-13.el8_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6729",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6729",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6731",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6731",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6731",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6736",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6736",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5602",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-23.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-24T00:00:00Z",
        "advisory": "RHSA-2026:5602",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-23.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6619",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "vim-2:8.2.2637-16.el9_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6620",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "vim-2:8.2.2637-20.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6540",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "vim-2:8.2.2637-20.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6539",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "vim-2:8.2.2637-22.el9_6.2"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-08T00:00:00Z",
        "advisory": "RHSA-2026:12274",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202604281506-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7239",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202604080111-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:15087",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202605060243-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14773",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202605060220-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10097",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202604211449-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17596",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202605112123-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8423",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202604140044-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7243",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202604080618-0"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7335",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1775740563"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16008",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1778244559"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16009",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1778244531"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9832",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1776868961"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1776868774"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1776868744"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1776868772"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-25749\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-25749\nhttps://github.com/vim/vim/commit/0714b15940b245108e6e9d7aa2260dd849a26fa9\nhttps://github.com/vim/vim/releases/tag/v9.1.2132\nhttps://github.com/vim/vim/security/advisories/GHSA-5w93-4g67-mm43"
    ],
    "name": "CVE-2026-25749",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-25T20:01:16Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP: Denial of Service via out-of-bounds read from malicious server input",
      "id": "2442756",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2442756"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_execute_result` indexes the global `error_code_names[]` array (7 elements, indices 0–6) with an unchecked `execResult->execResult` value received from the server, allowing an out-of-bounds read when the server sends an `execResult` value of 7 or greater. Version 3.23.0 fixes the issue.",
      "A flaw was found in FreeRDP. A malicious server can exploit this vulnerability by sending a specially crafted `execResult` value (7 or greater) to the client. This unchecked value is used to index an array, leading to an out-of-bounds read in the `xf_rail_server_execute_result` function. This can potentially cause a denial of service in the client application."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-25942\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-25942\nhttps://github.com/FreeRDP/FreeRDP/blob/3370e30e92a021eb680892dda14d642bc8b8727c/channels/rail/client/rail_orders.c#L528\nhttps://github.com/FreeRDP/FreeRDP/blob/3370e30e92a021eb680892dda14d642bc8b8727c/channels/rail/client/rail_orders.c#L75-L76\nhttps://github.com/FreeRDP/FreeRDP/blob/3370e30e92a021eb680892dda14d642bc8b8727c/client/X11/xf_rail.c#L1014-L1017\nhttps://github.com/FreeRDP/FreeRDP/blob/3370e30e92a021eb680892dda14d642bc8b8727c/client/X11/xf_rail.c#L40-L46\nhttps://github.com/FreeRDP/FreeRDP/commit/9362a0bf8dda04eedbca07d5dfaec1044e67cc6b\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-78q6-67m7-wwf6"
    ],
    "name": "CVE-2026-25942",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-25T20:24:07Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP: Denial of service due to use-after-free vulnerability",
      "id": "2442768",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2442768"
    },
    "cvss3": {
      "cvss3_base_score": "6.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` in `xf_rail_server_min_max_info` returns an unprotected pointer from the `railWindows` hash table, and the main thread can concurrently delete the window (via a window delete order) while the RAIL channel thread is still using the pointer. Version 3.23.0 fixes the issue.",
      "A flaw was found in FreeRDP. A remote attacker could exploit a use-after-free vulnerability in the `xf_SetWindowMinMaxInfo` function. This occurs when a freed window pointer is dereferenced because the main thread concurrently deletes a window while the Remote Desktop Protocol (RAIL) channel thread is still using the pointer. This flaw can lead to a denial of service."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16014",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "freerdp-2:3.10.3-5.el10_1.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19142",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freerdp-2:3.10.3-12.el10_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20605",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freerdp-2:3.10.3-3.el10_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20546",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "freerdp-0:2.1.1-5.el7_9.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16019",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "freerdp-2:2.11.7-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16482",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-1.el9_7.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19358",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-7.el9_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16485",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "freerdp-2:2.4.1-3.el9_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16483",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freerdp-2:2.4.1-6.el9_2.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16866",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "freerdp-2:2.11.2-1.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16865",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freerdp-2:2.11.7-1.el9_6.10"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-25952\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-25952\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1167\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1174\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1178\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1230-L1238\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L643\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_window.c#L1111\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_window.c#L1128\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_window.c#L1394\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_window.c#L1428\nhttps://github.com/FreeRDP/FreeRDP/commit/1994e9844212a6dfe0ff12309fef520e888986b5\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cgqm-cwjg-7w9x"
    ],
    "name": "CVE-2026-25952",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-25T20:27:00Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP: Denial of Service due to use-after-free vulnerability in window handling",
      "id": "2442757",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2442757"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reads from a freed `xfAppWindow` because the RDPGFX DVC thread obtains a bare pointer via `xf_rail_get_window` without any lifetime protection, while the main thread can concurrently delete the window through a fastpath window-delete order. Version 3.23.0 fixes the issue.",
      "A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. This use-after-free vulnerability occurs in the `xf_AppUpdateWindowFromSurface` function where a bare pointer to a window is obtained without proper lifetime protection. A remote attacker could exploit this by concurrently deleting the window while it is being accessed, leading to a read from freed memory. This could result in a denial of service (DoS) for the affected system."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-25953\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-25953\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1230-L1237\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L257-L290\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L643-L647\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_window.c#L1394-L1428\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_window.c#L1462-L1470\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_window.c#L1484-L1491\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/libfreerdp/gdi/gfx.c#L254-L286\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/libfreerdp/gdi/gfx.c#L278-L279\nhttps://github.com/FreeRDP/FreeRDP/commit/1994e9844212a6dfe0ff12309fef520e888986b5\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-p6rq-rxpc-rh3p"
    ],
    "name": "CVE-2026-25953",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-25T20:30:32Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP: Use-after-free vulnerability leading to denial of service",
      "id": "2442751",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2442751"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_local_move_size` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` returns an unprotected pointer from the `railWindows` hash table, and the main thread can concurrently delete the window (via a window delete order) while the RAIL channel thread is still using the pointer. Version 3.23.0 fixes the issue.",
      "A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP). A remote attacker could exploit a use-after-free vulnerability in the `xf_rail_server_local_move_size` function. This occurs because the `xf_rail_get_window` function returns an unprotected pointer, allowing a main thread to concurrently delete a window while another thread is still using its pointer. Successful exploitation of this flaw could lead to a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-25954\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-25954\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1076\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1133\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1230-L1238\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1347\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1350-L1359\nhttps://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L647\nhttps://github.com/FreeRDP/FreeRDP/commit/1994e9844212a6dfe0ff12309fef520e888986b5\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cc88-4j37-mw6j"
    ],
    "name": "CVE-2026-25954",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-16T11:11:00Z",
    "bugzilla": {
      "description": "evolution-data-server: Evolution Data Server: Arbitrary file deletion via inconsistent URI handling",
      "id": "2440301",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2440301"
    },
    "cvss3": {
      "cvss3_base_score": "5.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L",
      "status": "draft"
    },
    "cwe": "CWE-73",
    "details": [
      "A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.",
      "A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files."
    ],
    "statement": "This is a MODERATE impact flaw in evolution-data-server where inconsistent URI handling can lead to arbitrary file deletion. A Flatpak application with D-Bus access to the addressbook service can exploit this vulnerability by crafting a malicious URI with directory traversal sequences, potentially deleting critical Flatpak override files on the host filesystem.",
    "acknowledgement": "Red Hat would like to thank Codean Labs for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "evolution-data-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "evolution-data-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "evolution-data-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "evolution-data-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "evolution-data-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2604\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2604\nhttps://gitlab.gnome.org/GNOME/evolution-data-server/-/issues/627"
    ],
    "name": "CVE-2026-2604",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-02-11T00:00:00Z",
    "bugzilla": {
      "description": "busybox: BusyBox: Arbitrary file overwrite and potential code execution via incomplete path sanitization",
      "id": "2439039",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2439039"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-73",
    "details": [
      "A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.",
      "A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files."
    ],
    "acknowledgement": "Red Hat would like to thank Calil Khalil (Hakal) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13831",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "busybox-main-1.37.0-7.2.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "busybox",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-26157\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-26157\nhttps://git.busybox.net/busybox/commit/archival?id=3fb6b31c716669e12f75a2accd31bb7685b1a1cb"
    ],
    "name": "CVE-2026-26157",
    "mitigation": {
      "value": "As a prevention measure, avoid extracting archives from untrusted sources using BusyBox utilities. If extraction of untrusted archives is necessary, perform it within a highly isolated and restricted environment, such as a container with a read-only root filesystem and minimal privileges, to limit the potential impact of arbitrary file overwrites.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-02-11T00:00:00Z",
    "bugzilla": {
      "description": "busybox: BusyBox: Arbitrary file modification and privilege escalation via unvalidated tar archive entries",
      "id": "2439040",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2439040"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-73",
    "details": [
      "A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this flaw can lead to privilege escalation, enabling an attacker to gain unauthorized access to critical system files.",
      "A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this flaw can lead to privilege escalation, enabling an attacker to gain unauthorized access to critical system files."
    ],
    "acknowledgement": "Red Hat would like to thank Calil Khalil (Hakal) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13831",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "busybox-main-1.37.0-7.2.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "busybox",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-26158\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-26158\nhttps://git.busybox.net/busybox/commit/archival?id=3fb6b31c716669e12f75a2accd31bb7685b1a1cb"
    ],
    "name": "CVE-2026-26158",
    "mitigation": {
      "value": "As a prevention measure, avoid extracting tar archives from untrusted sources using BusyBox, especially when operating with elevated privileges. If processing untrusted archives is unavoidable, ensure that the extraction process is performed within a strictly sandboxed environment with minimal permissions. This operational control reduces the risk of arbitrary file modification and privilege escalation.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-02-25T20:47:14Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in GDI surface pipeline",
      "id": "2443132",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443132"
    },
    "cvss3": {
      "cvss3_base_score": "8.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-805",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The `gdi_SurfaceCommand_ClearCodec()` handler does not call `is_within_surface()` to validate the command rectangle against the destination surface dimensions, allowing attacker-controlled `cmd->left`/`cmd->top` (and subcodec rectangle offsets) to reach image copy routines that write into `surface->data` without bounds enforcement. The OOB write corrupts an adjacent `gdiGfxSurface` struct's `codecs*` pointer with attacker-controlled pixel data, and corruption of `codecs*` is sufficient to reach an indirect function pointer call (`NSC_CONTEXT.decode` at `nsc.c:500`) on a subsequent codec command — full instruction pointer (RIP) control demonstrated in exploitability harness. Users should upgrade to version 3.23.0 to receive a patch.",
      "A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP). A malicious RDP server can exploit a heap buffer overflow vulnerability by sending a specially crafted graphics command to a FreeRDP client. This allows the server to write data outside of its intended memory region, potentially leading to arbitrary code execution on the client system. The vulnerability occurs because the client does not properly validate the dimensions of incoming graphics commands."
    ],
    "statement": "A malicous RDP server may lead a heap buffer overflow in FreeRDP when the client is using the GDI surface pipeline. This happens when the server send a maliciously crafted RDPGFX ClearCodec command. When interpreting the command FreeRDP fails to validate the whether rectangle described by it falls within the destination surface dimension allowing the attacker to overwrite the surface data buffer without any boundaries check. Depending on the memory layout of the freerdp client's process it's possible to corrupt adjacent points leading to a remote code execution or force the freerdp client to crash.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5939",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "freerdp-2:3.10.3-5.el10_1.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19033",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freerdp-2:3.10.3-12.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5936",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freerdp-2:3.10.3-3.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7292",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "freerdp-0:2.1.1-5.el7_9.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6005",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "freerdp-2:2.11.7-4.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6712",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "freerdp-2:2.0.0-46.rc4.el8_2.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6616",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "freerdp-2:2.2.0-10.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6616",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "freerdp-2:2.2.0-10.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6665",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6665",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6665",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6764",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6764",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6004",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-1.el9_7.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6395",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "freerdp-2:2.4.1-3.el9_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6396",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freerdp-2:2.4.1-6.el9_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6384",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "freerdp-2:2.11.2-1.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6385",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freerdp-2:2.11.7-1.el9_6.5"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-26955\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-26955\nhttps://github.com/FreeRDP/FreeRDP/commit/7d8fdce2d0ef337cb86cb37fc0c436c905e04d77\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mr6w-ch7c-mqqj"
    ],
    "name": "CVE-2026-26955",
    "mitigation": {
      "value": "To mitigate this issue, avoid connecting to untrusted or unverified RDP servers. Users should only establish RDP connections with known and trusted servers. If connecting to untrusted servers is unavoidable, consider using a sandbox environment or a dedicated, isolated system for such connections to limit potential impact.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-02-25T20:59:17Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP: Arbitrary code execution via heap out-of-bounds write in RLE planar decode path",
      "id": "2442959",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2442959"
    },
    "cvss3": {
      "cvss3_base_score": "8.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, in the RLE planar decode path, `planar_decompress_plane_rle()` writes into `pDstData` at `((nYDst+y) * nDstStep) + (4*nXDst) + nChannel` without verifying that `(nYDst+nSrcHeight)` fits in the destination height or that `(nXDst+nSrcWidth)` fits in the destination stride. When `TempFormat != DstFormat`, `pDstData` becomes `planar->pTempData` (sized for the desktop), while `nYDst` is only validated against the **surface** by `is_within_surface()`. A malicious RDP server can exploit this to perform a heap out-of-bounds write with attacker-controlled offset and pixel data on any connecting FreeRDP client. The OOB write reaches up to 132,096 bytes past the temp buffer end, and  on the brk heap (desktop ≤ 128×128), an adjacent `NSC_CONTEXT` struct's `decode` function pointer is overwritten with attacker-controlled pixel data — control-flow–relevant corruption (function pointer overwritten) demonstrated under deterministic heap layout (`nsc->decode = 0xFF414141FF414141`). Version 3.23.0 fixes the vulnerability.",
      "A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP). A malicious RDP server can exploit a heap out-of-bounds write vulnerability in the `planar_decompress_plane_rle()` function. This vulnerability allows the server to write past the end of a temporary buffer, potentially overwriting critical data such as function pointers. This can lead to arbitrary code execution on the connecting FreeRDP client."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5939",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "freerdp-2:3.10.3-5.el10_1.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19033",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freerdp-2:3.10.3-12.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-03-26T00:00:00Z",
        "advisory": "RHSA-2026:5936",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freerdp-2:3.10.3-3.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7292",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "freerdp-0:2.1.1-5.el7_9.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6005",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "freerdp-2:2.11.7-4.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6712",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "freerdp-2:2.0.0-46.rc4.el8_2.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6616",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "freerdp-2:2.2.0-10.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6616",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "freerdp-2:2.2.0-10.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6665",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6665",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6665",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6764",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6764",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6004",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-1.el9_7.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6395",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "freerdp-2:2.4.1-3.el9_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6396",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freerdp-2:2.4.1-6.el9_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6384",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "freerdp-2:2.11.2-1.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6385",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freerdp-2:2.11.7-1.el9_6.5"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-26965\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-26965\nhttps://github.com/FreeRDP/FreeRDP/commit/a0be5cb87d760bb1c803ad1bb835aa1e73e62abc\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5vgf-mw4f-r33h"
    ],
    "name": "CVE-2026-26965",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-18T17:59:02Z",
    "bugzilla": {
      "description": "nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination",
      "id": "2448754",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448754"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-617",
    "details": [
      "nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.",
      "A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 frame, leading to an assertion failure and a denial of service (DoS)."
    ],
    "affected_release": [
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-nghttp2-0:1.64.0-3.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-nghttp2-0:1.64.0-3.el7jbcs"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7080",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nodejs22-1:22.22.2-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7666",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nghttp2-0:1.64.0-2.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7675",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nodejs24-1:24.14.1-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7310",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "nodejs22-1:22.22.2-2.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8868",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "nghttp2-0:1.64.0-2.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7123",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nodejs:22-8100020260331102257.6d880403"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7670",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nodejs:24-8100020260408131901.6d880403"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8339",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nodejs:20-8100020260414073138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7667",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "nghttp2-0:1.33.0-6.el8_10.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8541",
        "cpe": "cpe:/o:redhat:rhel_aus:8.2",
        "package": "nghttp2-0:1.33.0-3.el8_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8539",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "nghttp2-0:1.33.0-4.el8_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8539",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "nghttp2-0:1.33.0-4.el8_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8538",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "nghttp2-0:1.33.0-4.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8538",
        "cpe": "cpe:/o:redhat:rhel_tus:8.6",
        "package": "nghttp2-0:1.33.0-4.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8538",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.6",
        "package": "nghttp2-0:1.33.0-4.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8540",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "nghttp2-0:1.33.0-5.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8540",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "nghttp2-0:1.33.0-5.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7302",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nodejs:22-9070020260401095228.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7350",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nodejs:24-9070020260402152654.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7896",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nodejs:20-9070020260409073121.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7668",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "nghttp2-0:1.43.0-6.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8546",
        "cpe": "cpe:/o:redhat:rhel_e4s:9.0",
        "package": "nghttp2-0:1.43.0-5.el9_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8545",
        "cpe": "cpe:/o:redhat:rhel_e4s:9.2",
        "package": "nghttp2-0:1.43.0-5.el9_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9711",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nodejs:20-9040020260421133644.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8547",
        "cpe": "cpe:/o:redhat:rhel_eus:9.4",
        "package": "nghttp2-0:1.43.0-5.el9_4.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:7983",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nodejs:22-9060020260409121057.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9874",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nodejs:20-9060020260422064119.rhel9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8548",
        "cpe": "cpe:/o:redhat:rhel_eus:9.6",
        "package": "nghttp2-0:1.43.0-6.el9_6.1"
      },
      {
        "product_name": "Red Hat JBoss Core Services 2.4.62.SP4",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27201",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "nghttp2"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21695",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202605271418-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21690",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202605271328-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:15087",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202605060243-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14773",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202605060220-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20087",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202605200242-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17596",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202605112123-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21656",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202605260517-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20040",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202605201155-0"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1777325677"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1777325711"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-controller-rhel8:7.13.5-4.1777325710"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1777325680"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1777325709"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1777325680"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1777325708"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19724",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1779223654"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19725",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1779223651"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16008",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1778244559"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16009",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1778244531"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16030",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1778274666"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14937",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1778101579"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14937",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1778156756"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-03-30T00:00:00Z",
        "advisory": "RHSA-2026:6190",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nghttp2-main-1.68.1-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9832",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1776868961"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1776868774"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1776868744"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1776868772"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1777459441"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1777454300"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1777459504"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27135\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27135\nhttps://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1\nhttps://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6"
    ],
    "name": "CVE-2026-27135",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-08T01:06:57Z",
    "bugzilla": {
      "description": "cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names",
      "id": "2456341",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456341"
    },
    "cvss3": {
      "cvss3_base_score": "9.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-641",
    "details": [
      "SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.",
      "A flaw was found in the Go programming language (golang) and its command-line tool (cmd/go). A remote attacker could exploit this during the build process by crafting malicious SWIG (Simplified Wrapper and Interface Generator) file names that contain \"cgo\" and specific payloads. This could lead to code smuggling and arbitrary code execution, bypassing trust mechanisms and allowing the attacker to run unauthorized code."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10217",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "golang-0:1.25.9-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16024",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "golang-0:1.25.9-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10704",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "go-toolset:rhel8-8100020260422204008.a3795dee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16698",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "go-toolset:rhel8-8040020260505161557.5081a262"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16698",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "go-toolset:rhel8-8040020260505161557.5081a262"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16697",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "go-toolset:rhel8-8060020260505152018.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16697",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "go-toolset:rhel8-8060020260505152018.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16697",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "go-toolset:rhel8-8060020260505152018.97d7f71f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16694",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "go-toolset:rhel8-8080020260506150958.6b4b45d8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16694",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "go-toolset:rhel8-8080020260506150958.6b4b45d8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:10219",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "golang-0:1.25.9-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16494",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "golang-0:1.17.13-12.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16498",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "golang-0:1.19.13-25.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16497",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "golang-0:1.21.13-16.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16021",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "golang-0:1.25.9-1.el9_6"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34099",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1782184924"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25182",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1780978272"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-karpenter-provider-aws-rhel9:1780041462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/aws-kms-encryption-provider-rhel9:1780040098"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-kms-encryption-provider-rhel9:1780041224"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/azure-service-rhel9-operator:1780043978"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/cloud-network-config-controller-rhel9:1780040126"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/container-networking-plugins-microshift-rhel9:1780040410"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/egress-router-cni-rhel9:1780043779"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/frr-rhel9:1780041886"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-exporter-rhel9:1780043827"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/insights-runtime-extractor-rhel9:1780044940"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kube-metrics-server-rhel9:1780044576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/kubevirt-csi-driver-rhel9:1780044702"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/network-tools-rhel9:1780465170"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1780043484"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openshift-route-controller-manager-rhel9:1780042119"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/openstack-resource-controller-rhel9:1780041614"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-api-server-rhel9:1779779751"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-csr-approver-rhel9:1780044383"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1780462567"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-orchestrator-rhel9:1780044334"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-agent-installer-utils-rhel9:1780044523"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-apiserver-network-proxy-rhel9:1780043476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cloud-controller-manager-rhel9:1780040386"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-cluster-api-controllers-rhel9:1780040551"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1780040374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9-operator:1780040173"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-pod-identity-webhook-rhel9:1780040106"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-controller-manager-rhel9:1780040431"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cloud-node-manager-rhel9:1780040250"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-cluster-api-controllers-rhel9:1780040455"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1780040569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9-operator:1780040125"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-operator-rhel9:1780040115"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-file-csi-driver-rhel9:1780041802"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1780040474"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-cluster-api-controllers-rhel9:1780041847"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-installer-rhel9:1780462866"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-machine-controllers-rhel9:1780043216"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-rhel9-operator:1780041137"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-baremetal-runtimecfg-rhel9:1780041696"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-artifacts-rhel9:1780456268"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cli-rhel9:1780454976"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1780044088"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-api-rhel9:1780043838"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-authentication-rhel9-operator:1780043267"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9:1780043688"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-autoscaler-rhel9-operator:1780042895"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-baremetal-operator-rhel9:1780042508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-bootstrap-rhel9:1780043788"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-capi-rhel9-operator:1780077151"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-cloud-controller-manager-rhel9-operator:1780043389"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-api-rhel9:1780043841"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-config-rhel9-operator:1780040140"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator:1780044360"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator:1780043742"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-dns-rhel9-operator:1780044651"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-etcd-rhel9-operator:1780043209"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-image-registry-rhel9-operator:1780044985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-ingress-rhel9-operator:1780043338"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-apiserver-rhel9-operator:1780040877"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-cluster-api-rhel9-operator:1780043417"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-controller-manager-rhel9-operator:1780043063"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-scheduler-rhel9-operator:1780044416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1780041673"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-machine-approver-rhel9:1780077014"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-monitoring-rhel9-operator:1780043304"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-network-rhel9-operator:1780040117"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1780040462"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-olm-rhel9-operator:1780043588"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-apiserver-rhel9-operator:1780040365"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-openshift-controller-manager-rhel9-operator:1780044673"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-policy-controller-rhel9:1780042236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-samples-rhel9-operator:1780040315"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-storage-rhel9-operator:1780044883"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-version-rhel9-operator:1780043164"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-configmap-reloader-rhel9:1780042603"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9:1780365421"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-console-rhel9-operator:1780043143"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-container-networking-plugins-rhel9:1780043821"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-coredns-rhel9:1780042237"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9:1780041901"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-manila-rhel9-operator:1780041003"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-driver-nfs-rhel9:1780041501"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-attacher-rhel9:1780044427"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1780041753"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-resizer-rhel9:1780040144"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-snapshotter-rhel9:1780041782"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-livenessprobe-rhel9:1780040459"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1780041860"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-snapshot-controller-rhel9:1780044670"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-builder-rhel9:1780462456"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-docker-registry-rhel9:1780043300"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-etcd-rhel9:1780060002"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cloud-controller-manager-rhel9:1780041279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-cluster-api-controllers-rhel9:1780041069"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-operator-rhel9:1780042252"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-pd-csi-driver-rhel9:1780041162"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-gcp-workload-identity-federation-webhook-rhel9:1780040104"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1780060168"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hypershift-rhel9:1780044706"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-cluster-api-controllers-rhel9:1780041921"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-cloud-controller-manager-rhel9:1780040998"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibmcloud-machine-controllers-rhel9:1780040920"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9:1780040850"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:1780040338"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-image-customization-controller-rhel9:1780040138"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-insights-rhel9-operator:1780044358"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1780046879"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-installer-rhel9:1780059431"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ironic-machine-os-downloader-rhel9:1780365576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-proxy-rhel9:1780040812"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-rbac-proxy-rhel9:1780041732"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1780044865"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kube-storage-version-migrator-rhel9:1780041147"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-kubevirt-cloud-controller-manager-rhel9:1780041460"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-libvirt-machine-controllers-rhel9:1780462410"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-aws-rhel9:1780040278"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-azure-rhel9:1780040161"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-gcp-rhel9:1780040359"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-provider-openstack-rhel9:1780040470"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-api-rhel9-operator:1780045070"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1780384569"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-monitoring-plugin-rhel9:1780503846"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-admission-controller-rhel9:1780040131"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-microshift-rhel9:1780041461"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-cni-rhel9:1780040876"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-networkpolicy-rhel9:1780043841"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-route-override-cni-rhel9:1780040139"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-multus-whereabouts-ipam-cni-rhel9:1780043162"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-must-gather-rhel9:1780456062"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-interface-bond-cni-rhel9:1780040160"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-network-metrics-daemon-rhel9:1780043151"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-cloud-controller-manager-rhel9:1780040143"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-nutanix-machine-controllers-rhel9:1780040249"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-apiserver-rhel9:1780043773"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-proxy-rhel9:1780041035"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1780041508"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1780041774"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1780045015"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1780044994"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-controller-manager-rhel9:1780041206"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-state-metrics-rhel9:1780044407"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9:1780040576"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cinder-csi-driver-rhel9-operator:1780044692"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cloud-controller-manager-rhel9:1780044330"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openstack-cluster-api-controllers-rhel9:1780045024"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1780365324"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1780365279"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-marketplace-rhel9:1780042274"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1780365284"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1780046352"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1780056937"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-pod-rhel9:1780040715"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1780041386"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9-operator:1780040612"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-cloud-controller-manager-rhel9:1780293328"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-machine-controllers-rhel9:1780041754"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-alertmanager-rhel9:1780040283"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-config-reloader-rhel9:1780041841"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-node-exporter-rhel9:1780043953"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-operator-admission-webhook-rhel9:1780043165"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9:1780503869"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prometheus-rhel9-operator:1780040471"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-prom-label-proxy-rhel9:1780044248"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-service-ca-rhel9-operator:1780041841"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-telemeter-rhel9:1780043624"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tests-rhel9:1780466471"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-thanos-rhel9:1780320077"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-tools-rhel9:1780462550"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9:1780040430"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator:1780040095"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cloud-controller-manager-rhel9:1780040502"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-cluster-api-controllers-rhel9:1780040511"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9:1780040430"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-rhel9-operator:1780040095"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-csi-driver-syncer-rhel9:1780040119"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-vsphere-problem-detector-rhel9:1780040106"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9:1780044606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23246",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ovirt-csi-driver-rhel9-operator:1780044910"
      }
    ],
    "package_state": [
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-builder-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Under investigation",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-cni-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/pilot-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/ratelimit-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-builder-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Under investigation",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-cni-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-pilot-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "golang",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "golang1.25",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "golang1.26",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-docker-builder-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Under investigation",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27140\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27140\nhttps://go.dev/cl/763768\nhttps://go.dev/issue/78335\nhttps://groups.google.com/g/golang-announce/c/0uYbvbPZRWU\nhttps://pkg.go.dev/vuln/GO-2026-4871"
    ],
    "name": "CVE-2026-27140",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-06T21:28:14Z",
    "bugzilla": {
      "description": "html/template: URLs in meta content attribute actions are not escaped in html/template",
      "id": "2445351",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445351"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-79",
    "details": [
      "Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0.",
      "An input escaping flaw has been discovered in the golang html/template module. Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-03-20T00:00:00Z",
        "advisory": "RHSA-2026:5192",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-25-main-1.25.8-1.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7291",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-26-main-1.26.2-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "golang",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "go-toolset:rhel8/golang",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "golang",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "golang",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27142\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27142\nhttps://go.dev/cl/752081\nhttps://go.dev/issue/77954\nhttps://groups.google.com/g/golang-announce/c/EdhZqrQ98hk\nhttps://pkg.go.dev/vuln/GO-2026-4603"
    ],
    "name": "CVE-2026-27142",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-03T21:11:59Z",
    "bugzilla": {
      "description": "cups: OpenPrinting CUPS: Authorization bypass via case-insensitive username comparison",
      "id": "2454949",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454949"
    },
    "cvss3": {
      "cvss3_base_score": "6.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-178",
    "details": [
      "OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches.",
      "A flaw was found in OpenPrinting CUPS. This authorization bypass vulnerability allows an unprivileged user to gain unauthorized access to restricted operations. This can be exploited by using a username that differs only in case from an authorized user during authorization checks."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8814",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "cups-main-2.4.17-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27447\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27447\nhttps://github.com/OpenPrinting/cups/commit/88516bf6d9e34cef7a64a704b856b837f70cd220\nhttps://github.com/OpenPrinting/cups/security/advisories/GHSA-v987-m8hp-phj9"
    ],
    "name": "CVE-2026-27447",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-17T23:24:30Z",
    "bugzilla": {
      "description": "pyOpenSSL: TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback",
      "id": "2448508",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448508"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-636",
    "details": [
      "pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.",
      "A flaw was found in pyOpenSSL. The set_tlsext_servername_callback callback function can be used to implement Server Name Indication (SNI) during the TLS handshake. When the callback raises an unhandled exception, the handshake incorrectly proceeds instead of terminating. This fail-open behavior can allow an attacker to bypass SNI-based security controls and access restricted endpoints."
    ],
    "statement": "This flaw is only exploitable when an application using the pyOpenSSL library provides a custom callback to the set_tlsext_servername_callback function. For the handshake to proceed incorrectly, the callback must raise an unhandled exception, limiting the exposure of this issue. Due to these reasons, this vulnerability has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7224",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "pyopenssl-main-26.0.0-1.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ansible-dev-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "python3.11-pyOpenSSL",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "python3.12-pyOpenSSL",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "python3x-pyOpenSSL",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "python-pyOpenSSL",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "pyOpenSSL",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "pyOpenSSL",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "pyOpenSSL",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "pyOpenSSL",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "pyOpenSSL",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "pyOpenSSL",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "python3.12-pyOpenSSL",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "python-pyOpenSSL",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite-capsule:el8/python-pyOpenSSL",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite:el8/python-pyOpenSSL",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-insights-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Fix deferred",
        "package_name": "rhtas/model-transparency-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 4 for Cloud Providers",
        "fix_state": "Fix deferred",
        "package_name": "python-pyOpenSSL",
        "cpe": "cpe:/a:redhat:rhui:4::el8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27448\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27448\nhttps://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst#L27\nhttps://github.com/pyca/pyopenssl/commit/d41a814759a9fb49584ca8ab3f7295de49a85aa0\nhttps://github.com/pyca/pyopenssl/security/advisories/GHSA-vp96-hxj8-p424"
    ],
    "name": "CVE-2026-27448",
    "mitigation": {
      "value": "To mitigate this flaw, ensure the callback provided to the set_tlsext_servername_callback function is wrapped in a try/except block. This block should explicitly return a failure code instead of allowing the exception to propagate.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-03T21:23:00Z",
    "bugzilla": {
      "description": "util-linux: TOCTOU in the mount program when setting up loop devices",
      "id": "2454956",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454956"
    },
    "cvss3": {
      "cvss3_base_score": "4.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-367",
    "details": [
      "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
      "A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents."
    ],
    "statement": "This vulnerability is only exploitable when an `/etc/fstab` entry exists with `user,loop` options and its source path points to a directory where the attacker has write permission (e.g., the user's home directory). Also, this issue allows an attacker to mount any root-owned file or block device containing a valid filesystem, causing information disclosure. There is no memory corruption or arbitrary code execution. Due to these reasons, this flaw has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7180",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "util-linux-main-2.42-7.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "util-linux",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "util-linux-ng",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "util-linux",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "util-linux",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "util-linux",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27456\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27456\nhttps://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4\nhttps://github.com/util-linux/util-linux/releases/tag/v2.41.4\nhttps://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
    ],
    "name": "CVE-2026-27456",
    "mitigation": {
      "value": "To mitigate this flaw, remove the 'user' option from any loop mounts in the /etc/fstab file or ensure the the source path points to a root-owned directory where unprivileged users do not have write permissions.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-24T14:13:27Z",
    "bugzilla": {
      "description": "NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled",
      "id": "2450791",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450791"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in NGINX, specifically within the ngx_mail_auth_http_module. When this module is enabled, and CRAM-MD5 or APOP authentication is active with an authentication server that permits retries, undisclosed requests can cause NGINX worker processes to terminate. This can lead to a Denial of Service (DoS), making the affected NGINX instance unavailable to legitimate users."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6906",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nginx-2:1.26.3-2.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13634",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "nginx-2:1.26.3-1.el10_0.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6907",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nginx:1.24-8100020260401080144.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6923",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.24-9070020260331134728.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7002",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx-2:1.20.1-24.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7343",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.26-9070020260407080353.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15942",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "nginx-1:1.20.1-10.el9_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14836",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "nginx-1:1.20.1-14.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13839",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nginx-1:1.20.1-16.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15943",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nginx:1.24-9040020260504195322.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13680",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx-2:1.20.1-22.el9_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15945",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx:1.24-9060020260504194843.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15966",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx:1.26-9060020260504154614.9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8346",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nginx-main-1.30.0-1.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1776868774"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27651\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27651\nhttps://my.f5.com/manage/s/article/K000160383"
    ],
    "name": "CVE-2026-27651",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-24T14:13:26Z",
    "bugzilla": {
      "description": "NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module",
      "id": "2450776",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450776"
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in NGINX. A remote attacker can exploit a buffer overflow vulnerability within the ngx_http_dav_module module. This occurs when the NGINX configuration uses DAV module MOVE or COPY methods in conjunction with prefix location and alias directives. Successful exploitation may lead to the termination of the NGINX worker process, resulting in a Denial of Service (DoS), or allow for the modification of source or destination file names outside the intended document root."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6906",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nginx-2:1.26.3-2.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13634",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "nginx-2:1.26.3-1.el10_0.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6907",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nginx:1.24-8100020260401080144.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6923",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.24-9070020260331134728.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7002",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx-2:1.20.1-24.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7343",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.26-9070020260407080353.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15942",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "nginx-1:1.20.1-10.el9_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14836",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "nginx-1:1.20.1-14.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13839",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nginx-1:1.20.1-16.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15943",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nginx:1.24-9040020260504195322.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13680",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx-2:1.20.1-22.el9_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15945",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx:1.24-9060020260504194843.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15966",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx:1.26-9060020260504154614.9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8346",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nginx-main-1.30.0-1.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1776868774"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27654\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27654\nhttps://my.f5.com/manage/s/article/K000160382"
    ],
    "name": "CVE-2026-27654",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-24T14:13:25Z",
    "bugzilla": {
      "description": "NGINX: NGINX: Denial of Service due to memory corruption via crafted MP4 file",
      "id": "2450785",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450785"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. \nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in NGINX Open Source, specifically within the ngx_http_mp4_module. An attacker can exploit this memory corruption vulnerability by providing a specially crafted MP4 file. This can lead to an over-read or over-write of NGINX worker memory, causing the worker to terminate and resulting in a Denial of Service (DoS). This issue affects 32-bit NGINX Open Source when built with the ngx_http_mp4_module and the mp4 directive is used."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6906",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nginx-2:1.26.3-2.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13634",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "nginx-2:1.26.3-1.el10_0.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6907",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nginx:1.24-8100020260401080144.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6923",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.24-9070020260331134728.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7002",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx-2:1.20.1-24.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7343",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.26-9070020260407080353.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15942",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "nginx-1:1.20.1-10.el9_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14836",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "nginx-1:1.20.1-14.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13839",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nginx-1:1.20.1-16.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15943",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nginx:1.24-9040020260504195322.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13680",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx-2:1.20.1-22.el9_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15945",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx:1.24-9060020260504194843.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15966",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx:1.26-9060020260504154614.9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8346",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nginx-main-1.30.0-1.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1776868774"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27784\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27784\nhttps://my.f5.com/manage/s/article/K000160364"
    ],
    "name": "CVE-2026-27784",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-25T23:18:33Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Information disclosure via heap buffer over-read when processing images",
      "id": "2442872",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2442872"
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability occurs when processing an image with small dimension using the `-wavelet-denoise` operator. Versions 7.1.2-15 and 6.9.13-40 contain a patch.",
      "A flaw was found in ImageMagick. A local user could exploit a heap buffer over-read vulnerability by processing a specially crafted image with small dimensions using the `-wavelet-denoise` operator. This vulnerability may lead to the disclosure of sensitive information."
    ],
    "statement": "This MODERATE impact vulnerability in ImageMagick affects Red Hat Enterprise Linux. A heap buffer over-read can occur when processing images with small dimensions using the `-wavelet-denoise` operator. This flaw could lead to information disclosure or denial of service.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27798\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27798\nhttps://github.com/ImageMagick/ImageMagick/commit/0377e60b3c0d766bd7271221c95d9ee54f6a3738\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qpgx-jfcq-r59f\nhttps://github.com/dlemstra/Magick.NET/releases/tag/14.10.3"
    ],
    "name": "CVE-2026-27798",
    "mitigation": {
      "value": "To reduce exposure, avoid processing untrusted or maliciously crafted images with ImageMagick. If processing untrusted content is necessary, consider executing ImageMagick operations within a sandboxed environment to contain potential risks.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-25T23:20:25Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service and data corruption due to crafted DJVU image processing",
      "id": "2442879",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2442879"
    },
    "cvss3": {
      "cvss3_base_score": "4.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The vulnerability occurs due to integer truncation when calculating the stride (row size) for pixel buffer allocation. The stride calculation overflows a 32-bit signed integer, resulting in an out-of-bounds memory reads. Versions 7.1.2-15 and 6.9.13-40 contain a patch.",
      "A flaw was found in ImageMagick, a software suite used for editing and manipulating digital images. This vulnerability, a heap buffer over-read, exists within the component that handles DJVU image files. A local attacker could exploit this by processing a specially crafted DJVU image, leading to an error where the software miscalculates memory allocation due to an integer truncation. This causes the software to attempt to read memory outside its designated boundaries, which can result in a denial of service or potentially corrupt data."
    ],
    "statement": "This MODERATE impact vulnerability in ImageMagick involves a heap buffer over-read within the DJVU image format handler. The flaw occurs due to an integer truncation during stride calculation for pixel buffer allocation, leading to out-of-bounds memory reads when processing a specially crafted DJVU image. Red Hat Enterprise Linux 6 ELS and 7 ELS are affected.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27799\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27799\nhttps://github.com/ImageMagick/ImageMagick/commit/e87695b3227978ad70b967b8d054baaf8ac2cced\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r99p-5442-q2x2\nhttps://github.com/dlemstra/Magick.NET/releases/tag/14.10.3"
    ],
    "name": "CVE-2026-27799",
    "mitigation": {
      "value": "To mitigate this issue, avoid processing untrusted DJVU image files with ImageMagick. For server deployments, restrict network access to services that use ImageMagick for image processing. As an additional measure, consider disabling the DJVU delegate in ImageMagick's policy.xml configuration to prevent the processing of DJVU files. This may impact functionality that relies on DJVU image support.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-27T08:10:18Z",
    "bugzilla": {
      "description": "dovecot: Dovecot: Replay attack allows unauthorized login via observed One-Time Password (OTP) exchange",
      "id": "2452177",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452177"
    },
    "cvss3": {
      "cvss3_base_score": "6.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
      "status": "draft"
    },
    "cwe": "CWE-294",
    "details": [
      "Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.",
      "A flaw was found in Dovecot. Under specific conditions, if the authentication cache is enabled and the username is altered in the password database, Dovecot's One-Time Password (OTP) authentication is vulnerable to a replay attack. A remote attacker able to observe an OTP exchange can exploit this flaw to log in as the legitimate user, leading to unauthorized access."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27855\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27855\nhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json"
    ],
    "name": "CVE-2026-27855",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-27T08:10:19Z",
    "bugzilla": {
      "description": "dovecot: Doveadm: Full access via timing oracle attack in credential verification",
      "id": "2452171",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452171"
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-208",
    "details": [
      "Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.",
      "A flaw was found in Doveadm, a component of Dovecot. An attacker can exploit a timing oracle vulnerability during the direct comparison of credentials. This allows the attacker to determine the configured credentials, potentially leading to full unauthorized access to the affected component."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26564",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "dovecot-1:2.2.36-8.el7_9.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27856\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27856\nhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json"
    ],
    "name": "CVE-2026-27856",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-27T08:10:20Z",
    "bugzilla": {
      "description": "dovecot: denial of service via specially crafted NOOP command",
      "id": "2452179",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452179"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Sending \"NOOP (((...)))\" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.",
      "A flaw was found in dovecot. An unauthenticated and remote attacker can send a specially crafted \"NOOP\" command containing numerous open and close parentheses without a command-ending line feed, causing the server to allocate an excessive amount of memory, resulting in a denial of service."
    ],
    "statement": "This flaw allows an unauthenticated and remote attacker to cause a denial of service via a specially crafted \"NOOP\" command. Due to this reason, this vulnerability has been rated with an important severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13498",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "dovecot-1:2.3.21-16.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19149",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "dovecot-1:2.3.21-19.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17602",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "dovecot-1:2.3.21-16.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26564",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "dovecot-1:2.2.36-8.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13830",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "dovecot-1:2.3.16-7.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19455",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "dovecot-1:2.3.8-9.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19455",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "dovecot-1:2.3.8-9.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19453",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "dovecot-1:2.3.16-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19453",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "dovecot-1:2.3.16-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19453",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "dovecot-1:2.3.16-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18053",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "dovecot-1:2.3.16-3.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18053",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "dovecot-1:2.3.16-3.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13857",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "dovecot-1:2.3.16-15.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19364",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "dovecot-1:2.3.16-18.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17630",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "dovecot-1:2.3.16-3.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17628",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "dovecot-1:2.3.16-8.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17625",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "dovecot-1:2.3.16-11.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17626",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "dovecot-1:2.3.16-15.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27857\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27857\nhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json"
    ],
    "name": "CVE-2026-27857",
    "mitigation": {
      "value": "Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-27T08:10:21Z",
    "bugzilla": {
      "description": "dovecot: denial of service via crafted message before authentication",
      "id": "2452175",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452175"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.\nAttacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.",
      "A flaw was found in dovecot. An unauthenticated and remote attacker can send a crafted message that causes managesieve to allocate an excessive amount of memory, forcing managesieve-login to be unavailable by repeatedly crashing the process, resulting in a denial of service."
    ],
    "statement": "This flaw allows an unauthenticated and remote attacker to cause a denial of service via a specially crafted message. Due to this reason, this vulnerability has been rated with an important severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13498",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "dovecot-1:2.3.21-16.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19149",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "dovecot-1:2.3.21-19.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17602",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "dovecot-1:2.3.21-16.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26564",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "dovecot-1:2.2.36-8.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13830",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "dovecot-1:2.3.16-7.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19455",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "dovecot-1:2.3.8-9.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19455",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "dovecot-1:2.3.8-9.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19453",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "dovecot-1:2.3.16-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19453",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "dovecot-1:2.3.16-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19453",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "dovecot-1:2.3.16-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18053",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "dovecot-1:2.3.16-3.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18053",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "dovecot-1:2.3.16-3.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13857",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "dovecot-1:2.3.16-15.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19364",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "dovecot-1:2.3.16-18.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17630",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "dovecot-1:2.3.16-3.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17628",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "dovecot-1:2.3.16-8.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17625",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "dovecot-1:2.3.16-11.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17626",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "dovecot-1:2.3.16-15.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27858\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27858\nhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json"
    ],
    "name": "CVE-2026-27858",
    "mitigation": {
      "value": "To mitigate this vulnerability, protect access to the managesieve protocol by configuring firewall rules to restrict access to the managesieve port and only allow connections from trusted IP addresses or networks.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-27T08:10:22Z",
    "bugzilla": {
      "description": "dovecot: Dovecot: Denial of Service via excessive RFC 2231 MIME parameters",
      "id": "2452180",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452180"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-770",
    "details": [
      "A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume large amounts of CPU time. Use MTA capabilities to limit RFC 2231 MIME parameters in mail messages, or upgrade to fixed version where the processing is limited. No publicly available exploits are known.",
      "A flaw was found in Dovecot. A remote attacker can exploit this vulnerability by sending a specially crafted mail message containing an excessive amount of RFC 2231 MIME parameters. This can cause the Local Mail Transfer Protocol (LMTP) process to consume large amounts of CPU time, leading to a Denial of Service (DoS)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27859\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27859\nhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json"
    ],
    "name": "CVE-2026-27859",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segments arrive out of order, the Array class's grow() method computes a negative size value, causing a SIGSEGV crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27890\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27890"
    ],
    "name": "CVE-2026-27890",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-25T21:07:30Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP: Denial of Service via endless blocking loop in Stream_EnsureCapacity",
      "id": "2442783",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2442783"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the function `Stream_EnsureCapacity` can create an endless blocking loop. This may affect all client and server implementations using `FreeRDP`. For practical exploitation this will only work on 32bit systems where the available physical memory is `>= SIZE_MAX`. Version 3.23.0 contains a patch. No known workarounds are available.",
      "A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. The `Stream_EnsureCapacity` function can create an endless blocking loop, leading to a Denial of Service (DoS). This vulnerability can be exploited on 32-bit systems where the available physical memory is greater than or equal to the `SIZE_MAX` variable, potentially affecting both client and server implementations using FreeRDP."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20546",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "freerdp-0:2.1.1-5.el7_9.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16019",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "freerdp-2:2.11.7-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16482",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-1.el9_7.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19358",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-7.el9_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16485",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "freerdp-2:2.4.1-3.el9_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16483",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freerdp-2:2.4.1-6.el9_2.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16866",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "freerdp-2:2.11.2-1.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16865",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freerdp-2:2.11.7-1.el9_6.10"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-27951\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-27951\nhttps://github.com/FreeRDP/FreeRDP/commit/118afc0b954ba9d5632b7836ad24e454555ed113\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qcfc-ghxr-h927"
    ],
    "name": "CVE-2026-27951",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when processing an op_slice network packet, the server passes an unprepared structure containing a null pointer to the SDL_info() function, resulting in a null pointer dereference and server crash. An unauthenticated attacker can trigger this by sending a crafted packet to the server port. This issue has been fixed in versions 6.0.0, 5.0.4, 4.0.7 and 3.0.14."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28212\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28212"
    ],
    "name": "CVE-2026-28212",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize() function can overflow the totalLength value when parsing a Wide type clumplet, causing an infinite loop. An authenticated user with INSERT privileges on any table can exploit this via a crafted Batch Parameter Block to cause a denial of service against the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28214\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28214"
    ],
    "name": "CVE-2026-28214",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, the port_server_crypt_callback handler is not initialized, resulting in a null pointer dereference and server crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28224\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28224"
    ],
    "name": "CVE-2026-28224",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-02-26T00:00:00Z",
    "bugzilla": {
      "description": "gvfs: GVfs FTP backend: Information disclosure via untrusted PASV responses",
      "id": "2443004",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443004"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-918",
    "details": [
      "A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe for open ports accessible from the client's network.",
      "A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe for open ports accessible from the client's network."
    ],
    "statement": "This is a LOW impact information disclosure flaw in the GVfs FTP backend. A client connecting to a malicious FTP server could be coerced into probing for open ports accessible from the client's network, as the client unconditionally trusts the IP address and port provided in passive mode (PASV) responses. This vulnerability requires user interaction with a compromised or malicious FTP server.",
    "acknowledgement": "Red Hat would like to thank Codean Labs for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gvfs",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "gvfs",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "gvfs",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gvfs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gvfs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28295\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28295"
    ],
    "name": "CVE-2026-28295",
    "mitigation": {
      "value": "To mitigate this issue, users should avoid connecting to untrusted or unknown FTP servers when using applications that rely on the GVfs FTP backend. This vulnerability requires the client to interact with a malicious FTP server for exploitation.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-26T00:00:00Z",
    "bugzilla": {
      "description": "gvfs: FTP GVfs backend: Arbitrary FTP command injection via CRLF sequences in file paths",
      "id": "2443003",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443003"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-93",
    "details": [
      "A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbitrary FTP commands, potentially leading to arbitrary code execution or other severe impacts.",
      "A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbitrary FTP commands, potentially leading to arbitrary code execution or other severe impacts."
    ],
    "statement": "The GVfs FTP backend is vulnerable to command injection due to improper sanitization of user-supplied file paths. An attacker could craft a malicious FTP path containing CRLF sequences to inject arbitrary FTP commands. This primarily impacts systems where users interact with untrusted FTP servers or open specially crafted FTP links through applications utilizing GVfs, typically in desktop environments.",
    "acknowledgement": "Red Hat would like to thank Codean Labs for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gvfs",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "gvfs",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "gvfs",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gvfs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gvfs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28296\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28296"
    ],
    "name": "CVE-2026-28296",
    "mitigation": {
      "value": "To reduce the risk associated with this vulnerability, users should avoid connecting to untrusted FTP servers or opening FTP links from unverified sources. Implementing network-level restrictions, such as firewall rules, to limit outbound connections to only trusted FTP servers can further mitigate potential exposure. If the GVfs FTP backend is not essential for daily operations, consider removing or disabling packages that provide this functionality, though this action may affect other desktop environment features that rely on GVfs for FTP access.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-07T00:00:00Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication",
      "id": "2451098",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451098"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-1341",
    "details": [
      "Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.",
      "A flaw was found in OpenSSL. An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. This vulnerability could lead to data corruption, application crashes, or, in severe cases, arbitrary code execution. This issue is highly specific and uncommon, as it only affects clients using both PKIX-TA(0)/PKIX-EE(1) and DANE-TA(2) certificate usages and communicating with a server publishing a TLSA record set with both types of records."
    ],
    "statement": "This Low impact vulnerability affects clients performing DANE TLSA-based server authentication only when configured with an uncommon combination of PKIX-TA(0/PKIX-EE(1) and DANE-TA(2) certificate usages. Most common SMTP MTA deployments are not vulnerable as they are recommended to treat PKIX certificate usages as unusable. Exploitation also requires communication with a server publishing a TLSA RRset with both types of records.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7261",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssl-main-3.5.6-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Under investigation",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Under investigation",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Under investigation",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Under investigation",
        "package_name": "openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28387\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28387\nhttps://openssl-library.org/news/secadv/20260407.txt"
    ],
    "name": "CVE-2026-28387",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-07T00:00:00Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing",
      "id": "2451097",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451097"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
      "A flaw was found in OpenSSL. When processing a malformed delta Certificate Revocation List (CRL) that lacks a required CRL Number extension, a NULL pointer dereference can occur. This vulnerability can be exploited by a remote attacker who provides a specially crafted delta CRL to an application that has delta CRL processing enabled, leading to a Denial of Service (DoS) for the application."
    ],
    "statement": "Low impact. This vulnerability in X.509 certificate verification can lead to a Denial of Service (DoS) due to a NULL pointer dereference when processing a malformed delta Certificate Revocation List (CRL). Exploitation requires the `X509_V_FLAG_USE_DELTAS` flag to be enabled in the verification context, a certificate with a `freshestCRL` extension or a base CRL with `EXFLAG_FRESHEST` set, and an attacker-provided malformed CRL. This flaw is limited to DoS and does not allow for code execution or memory disclosure.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7261",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssl-main-3.5.6-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28388\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28388\nhttps://openssl-library.org/news/secadv/20260407.txt"
    ],
    "name": "CVE-2026-28388",
    "mitigation": {
      "value": "To mitigate this issue, ensure that delta CRL processing is not enabled in applications that do not require it. This vulnerability is only exploitable when the `X509_V_FLAG_USE_DELTAS` flag is explicitly set within the X.509 verification context. Review application configurations to confirm that this flag is not enabled unless absolutely necessary for your security policy. Disabling this flag will prevent the vulnerable code path from being exercised. Specific implementation details will vary depending on the application utilizing X.509 certificate verification.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-07T00:00:00Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Denial of Service vulnerability in CMS processing",
      "id": "2451096",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451096"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-166",
    "details": [
      "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "A flaw was found in OpenSSL. A remote attacker could exploit this by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message with KeyAgreeRecipientInfo. This vulnerability arises because the software attempts to process an optional field without verifying its existence, leading to a NULL pointer dereference. This can result in a Denial of Service (DoS) for applications that handle untrusted CMS data."
    ],
    "statement": "This Low impact flaw affects applications processing Cryptographic Message Syntax (CMS) data, specifically crafted CMS EnvelopedData messages with KeyAgreeRecipientInfo. A NULL pointer dereference can occur if the optional parameters field of KeyEncryptionAlgorithmIdentifier is missing, leading to a Denial of Service. Red Hat products are vulnerable if they call `CMS_decrypt()` or `PKCS7_decrypt()` on untrusted input, such as in S/MIME processing or CMS-based protocols.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7261",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssl-main-3.5.6-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28389\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28389\nhttps://openssl-library.org/news/secadv/20260407.txt"
    ],
    "name": "CVE-2026-28389",
    "mitigation": {
      "value": "To mitigate this issue, avoid processing untrusted CMS EnvelopedData messages with KeyAgreeRecipientInfo. Restrict network access to services that process CMS data from untrusted sources. If possible, configure applications to only accept CMS data from trusted origins. This operational control helps reduce exposure to the vulnerability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-07T22:00:54Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing",
      "id": "2456314",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456314"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "A flaw was found in OpenSSL. A remote attacker could exploit this vulnerability by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message. During the processing of a KeyTransportRecipientInfo with RSA-OAEP encryption, the system attempts to access an optional parameter field without first verifying its presence. This leads to a NULL pointer dereference, which can cause applications processing the attacker-controlled CMS data to crash, resulting in a Denial of Service (DoS)."
    ],
    "statement": "This CVE has been rated as moderate by redhat because the vulnerability is limited to a denial-of-service condition caused by a NULL pointer dereference in OpenSSL CMS processing, without evidence of memory corruption or code execution, furthermore the Affected functionality is niche. The vulnerable path requires:\nCMS/S/MIME processing,\nspecifically CMS_decrypt(),\nwith RSA-OAEP KeyTransportRecipientInfo.\nMany OpenSSL consumers never use CMS APIs, never process S/MIME,\nor do not decrypt attacker-controlled CMS objects.\nSo exposure is far narrower than a generic TLS parsing vulnerability.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22314",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "openssl-1:3.5.5-3.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39297",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "edk2-0:20251114-5.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58563",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "openssl-1:1.0.2k-26.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22315",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "compat-openssl10-1:1.0.2o-4.el8_10.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38503",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "openssl-1:1.1.1k-17.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47096",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "compat-openssl10-1:1.0.2o-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43513",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "openssl-1:1.1.1g-18.el8_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47096",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "compat-openssl10-1:1.0.2o-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43513",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "openssl-1:1.1.1g-18.el8_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44480",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "compat-openssl10-1:1.0.2o-4.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38804",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "openssl-1:1.1.1k-17.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44480",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "compat-openssl10-1:1.0.2o-4.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38804",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "openssl-1:1.1.1k-17.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36217",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "compat-openssl10-1:1.0.2o-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38805",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "openssl-1:1.1.1k-17.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36217",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "compat-openssl10-1:1.0.2o-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38805",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "openssl-1:1.1.1k-17.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22312",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-3.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22313",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "compat-openssl11-1:1.1.1k-5.el9_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22312",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-3.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:39012",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "compat-openssl11-1:1.1.1k-4.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:39009",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "compat-openssl11-1:1.1.1k-5.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35869",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "compat-openssl11-1:1.1.1k-5.el9_6.3"
      },
      {
        "product_name": "Cost Management Metrics Operator 4",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27998",
        "cpe": "cpe:/a:redhat:cost_management:4::el9",
        "package": "costmanagement/costmanagement-metrics-rhel9-operator:1780946239"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-06-09T00:00:00Z",
        "advisory": "RHSA-2026:24866",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-chatbot-rhel9:1780102732"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14937",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1778101579"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14217",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssl-main-3.5.6-0.3.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7261",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssl-main-3.5.6-0.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22634",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1780420428"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Cluster Operator",
        "fix_state": "Affected",
        "package_name": "confidential-clusters-beta/confidential-cluster-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_cluster_operator:4"
      },
      {
        "product_name": "Confidential Cluster Operator",
        "fix_state": "Affected",
        "package_name": "redhat-user-workloads/attestation-key-register",
        "cpe": "cpe:/a:redhat:confidential_cluster_operator:4"
      },
      {
        "product_name": "Confidential Cluster Operator",
        "fix_state": "Affected",
        "package_name": "redhat-user-workloads/buildroot",
        "cpe": "cpe:/a:redhat:confidential_cluster_operator:4"
      },
      {
        "product_name": "Confidential Cluster Operator",
        "fix_state": "Affected",
        "package_name": "redhat-user-workloads/compute-pcrs",
        "cpe": "cpe:/a:redhat:confidential_cluster_operator:4"
      },
      {
        "product_name": "Confidential Cluster Operator",
        "fix_state": "Affected",
        "package_name": "redhat-user-workloads/confidential-cluster-operator",
        "cpe": "cpe:/a:redhat:confidential_cluster_operator:4"
      },
      {
        "product_name": "Confidential Cluster Operator",
        "fix_state": "Affected",
        "package_name": "redhat-user-workloads/registration-server",
        "cpe": "cpe:/a:redhat:confidential_cluster_operator:4"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "redhat-user-workloads/osc-monitor",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/osc-monitor-v1-10",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "redhat-user-workloads/osc-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/osc-operator-bundle-v1-10",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/osc-operator-v1-10",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "redhat-user-workloads/osc-podvm-builder",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/osc-podvm-builder-v1-10",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "redhat-user-workloads/osc-podvm-payload",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/osc-podvm-payload-v1-10",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "redhat-user-workloads/trustee",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Affected",
        "package_name": "lightspeed-core/dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/art-images",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "redhat-user-workloads/logging-vector-v6-2",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "redhat-user-workloads/logging-vector-v6-4",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Will not fix",
        "package_name": "redhat-user-workloads/art-images",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Under investigation",
        "package_name": "multicluster-engine/clusterlifecycle-state-metrics-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-to-dataverse-exporter",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/ossm-3-3-ztunnel",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Affected",
        "package_name": "redhat-user-workloads/pen-drive-scanner",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:0"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp21/backend",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp22/backend",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Will not fix",
        "package_name": "3scale-amp2/backend-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Under investigation",
        "package_name": "rhacm2/acm-governance-policy-addon-controller-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Under investigation",
        "package_name": "rhacm2/acm-governance-policy-framework-addon-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Under investigation",
        "package_name": "rhacm2/config-policy-controller-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Under investigation",
        "package_name": "rhacm2/governance-policy-propagator-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Under investigation",
        "package_name": "rhacm2/klusterlet-addon-controller-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Will not fix",
        "package_name": "rhacs-eng/release-fact",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/automation-reports",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-26/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-26/mcp-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-26/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Affected",
        "package_name": "redhat-user-workloads/rhcl-1-3-limitador",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Directory Server 11",
        "fix_state": "Not affected",
        "package_name": "redhat-ds:11/389-ds-base",
        "cpe": "cpe:/a:redhat:directory_server:11"
      },
      {
        "product_name": "Red Hat Directory Server 12",
        "fix_state": "Not affected",
        "package_name": "redhat-ds:12/389-ds-base",
        "cpe": "cpe:/a:redhat:directory_server:12"
      },
      {
        "product_name": "Red Hat Directory Server 13",
        "fix_state": "Not affected",
        "package_name": "389-ds-base",
        "cpe": "cpe:/a:redhat:directory_server:13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "389-ds-base",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Will not fix",
        "package_name": "clevis-pin-tpm2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "gjs",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "keylime-agent-rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "mesa",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "python3.14-cryptography",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rpm-ostree",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "ruby4.0",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Will not fix",
        "package_name": "rust-afterburn",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "rust-bootupd",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rust-sequoia-sq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rust-sequoia-sqv",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Will not fix",
        "package_name": "samba",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "virt-firmware-rs",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "389-ds:1.4/389-ds-base",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "mozjs60",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python3.12-cryptography",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "rpm-ostree",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "ruby:3.3/ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "389-ds-base",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "gjs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "keylime-agent-rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "mesa",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python3.12-cryptography",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python3.14-cryptography",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "rpm-ostree",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "ruby:3.3/ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "ruby:4.0/ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rust-bootupd",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rust-rpm-sequoia",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "samba",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Will not fix",
        "package_name": "openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat Offline Knowledge Portal",
        "fix_state": "Affected",
        "package_name": "redhat-user-workloads/rhokp-core-encrypted",
        "cpe": "cpe:/a:redhat:offline_knowledge_portal:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-fms-guardrails-orchestrator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llm-d-inference-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-vllm-orchestrator-gateway-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "conmon-rs",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "rpm-ostree",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "rust-bootupd",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Update Service",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/osus-operand",
        "cpe": "cpe:/a:redhat:openshift_update_service:5"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/quay-quay-v3-10",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/quay-quay-v3-12",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/quay-quay-v3-13",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/quay-quay-v3-14",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/quay-quay-v3-15",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/quay-quay-v3-16",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/quay-quay-v3-17",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/quay-quay-v3-9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/iop-advisor-backend-sat-6-18",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/iop-advisor-engine",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/iop-host-inventory-sat-6-18",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/iop-vmaas-sat-6-18",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/iop-vulnerability-engine-sat-6-18",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "securesign/cli-tuftool",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "securesign/tuffer",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Affected",
        "package_name": "redhat-user-workloads/rhtpa-product-0-3-z",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28390\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28390\nhttps://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc\nhttps://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6\nhttps://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4\nhttps://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788\nhttps://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75\nhttps://openssl-library.org/news/secadv/20260407.txt"
    ],
    "name": "CVE-2026-28390",
    "mitigation": {
      "value": "Applications that process Cryptographic Message Syntax (CMS) EnvelopedData messages should be configured to only accept input from trusted sources. Restricting network access to services that process untrusted CMS data can also reduce exposure to this Denial of Service vulnerability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-27T21:54:35Z",
    "bugzilla": {
      "description": "vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin",
      "id": "2443455",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443455"
    },
    "cvss3": {
      "cvss3_base_score": "4.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-78",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.",
      "A flaw was found in Vim, an open-source command-line text editor. Specifically, an operating system (OS) command injection vulnerability exists in the `netrw` standard plugin. A remote attacker could exploit this by tricking a user into opening a specially crafted URL, such as one using the `scp://` protocol handler. Successful exploitation allows the attacker to execute arbitrary shell commands with the same privileges as the Vim process, leading to potential system compromise."
    ],
    "statement": "The risk posed by this vulnerability is limited on Red Hat products due to user and system isolation features which are enabled by default. The impacts of this flaw will be limited by the active user's permissions and access control limits. Host systems are not at risk when following Red Hat guidelines and the root user account is not actively executing Vim.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7711",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "vim-2:9.1.083-6.el10_1.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6502",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6617",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "vim-2:7.4.629-8.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6915",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-22.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6915",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-22.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6730",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "vim-2:8.0.1763-13.el8_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6729",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6729",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6731",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6731",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6731",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6736",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6736",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8259",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-23.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8259",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-23.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6619",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "vim-2:8.2.2637-16.el9_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6620",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "vim-2:8.2.2637-20.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6540",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "vim-2:8.2.2637-20.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6539",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "vim-2:8.2.2637-22.el9_6.2"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-08T00:00:00Z",
        "advisory": "RHSA-2026:12274",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202604281506-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7239",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202604080111-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:15087",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202605060243-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14773",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202605060220-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10097",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202604211449-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17596",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202605112123-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8423",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202604140044-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7243",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202604080618-0"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7335",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1775740563"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16008",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1778244559"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16009",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1778244531"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9832",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1776868961"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1776868774"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1776868744"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1776868772"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1777459441"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1777454300"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1777459504"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28417\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28417\nhttps://github.com/vim/vim/commit/79348dbbc09332130f4c860\nhttps://github.com/vim/vim/releases/tag/v9.2.0073\nhttps://github.com/vim/vim/security/advisories/GHSA-m3xh-9434-g336"
    ],
    "name": "CVE-2026-28417",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-27T21:58:37Z",
    "bugzilla": {
      "description": "vim: Vim: Information disclosure via heap-based buffer overflow in Emacs-style tags file parsing",
      "id": "2443481",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443481"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file, Vim can be tricked into reading up to 7 bytes beyond the allocated memory boundary. Version 9.2.0074 fixes the issue.",
      "A flaw was found in Vim. When processing a specially crafted Emacs-style tags file, a heap-based buffer overflow out-of-bounds read vulnerability allows an attacker to trick Vim into reading up to 7 bytes beyond its allocated memory boundary. This could lead to information disclosure or potentially affect the integrity of the application."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28418\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28418\nhttps://github.com/vim/vim/commit/f6a7f469a9c0d09e84cd6cb\nhttps://github.com/vim/vim/releases/tag/v9.2.0074\nhttps://github.com/vim/vim/security/advisories/GHSA-h4mf-vg97-hj8j"
    ],
    "name": "CVE-2026-28418",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-27T22:02:55Z",
    "bugzilla": {
      "description": "vim: Vim: Information disclosure and denial of service via malformed tags file",
      "id": "2443482",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443482"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "status": "draft"
    },
    "cwe": "CWE-124",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file where a delimiter appears at the start of a line, Vim attempts to read memory immediately preceding the allocated buffer. Version 9.2.0075 fixes the issue.",
      "A flaw was found in Vim, an open-source command-line text editor. This vulnerability, a heap-based buffer underflow, occurs when Vim processes a specially crafted Emacs-style tags file. If a malicious file with a delimiter at the start of a line is opened, Vim attempts to read memory outside its designated area. This could lead to the disclosure of sensitive information or cause the application to crash, resulting in a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28419\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28419\nhttps://github.com/vim/vim/commit/9b7dfa2948c9e1e5e32a5812\nhttps://github.com/vim/vim/releases/tag/v9.2.0075\nhttps://github.com/vim/vim/security/advisories/GHSA-xcc8-r6c5-hvwv"
    ],
    "name": "CVE-2026-28419",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-27T22:04:36Z",
    "bugzilla": {
      "description": "vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator",
      "id": "2443484",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443484"
    },
    "cvss3": {
      "cvss3_base_score": "4.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.",
      "A flaw was found in Vim. A remote attacker could exploit a heap-based buffer overflow and an out-of-bounds read vulnerability in Vim's terminal emulator. This occurs when processing specially crafted Unicode supplementary plane characters, potentially leading to information disclosure and denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28420\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28420\nhttps://github.com/vim/vim/commit/bb6de2105b160e729c34063\nhttps://github.com/vim/vim/releases/tag/v9.2.0076\nhttps://github.com/vim/vim/security/advisories/GHSA-rvj2-jrf9-2phg"
    ],
    "name": "CVE-2026-28420",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-02-27T22:06:34Z",
    "bugzilla": {
      "description": "vim: Vim: Denial of service and information disclosure via crafted swap file",
      "id": "2443474",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443474"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read from crafted pointer blocks within a swap file. Version 9.2.0077 fixes the issue.",
      "A flaw was found in Vim. This vulnerability, a heap-buffer-overflow and a segmentation fault, exists in the swap file recovery logic. A local attacker could exploit this by providing a specially crafted swap file. This could lead to a denial of service (DoS) or potentially information disclosure."
    ],
    "statement": "The risk posed by this vulnerability is limited on Red Hat products due to user and system isolation features which are enabled by default. The impacts of this flaw will be limited by the active user's permissions and access control limits. Host systems are not at risk when following Red Hat guidelines and the root user account is not actively executing Vim.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7711",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "vim-2:9.1.083-6.el10_1.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6502",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6617",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "vim-2:7.4.629-8.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6915",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-22.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6915",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-22.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6730",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "vim-2:8.0.1763-13.el8_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6729",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6729",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6731",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6731",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6731",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6736",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6736",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8259",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-23.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8259",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-23.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6619",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "vim-2:8.2.2637-16.el9_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6620",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "vim-2:8.2.2637-20.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6540",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "vim-2:8.2.2637-20.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6539",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "vim-2:8.2.2637-22.el9_6.2"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-08T00:00:00Z",
        "advisory": "RHSA-2026:12274",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202604281506-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7239",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202604080111-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:15087",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202605060243-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14773",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202605060220-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10097",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202604211449-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17596",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202605112123-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8423",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202604140044-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7243",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202604080618-0"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7335",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1775740563"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16008",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1778244559"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16009",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1778244531"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9832",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1776868961"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1776868774"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1776868744"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1776868772"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1777459441"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1777454300"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1777459504"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28421\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28421\nhttps://github.com/vim/vim/commit/65c1a143c331c886dc28\nhttps://github.com/vim/vim/releases/tag/v9.2.0077\nhttps://github.com/vim/vim/security/advisories/GHSA-r2gw-2x48-jj5p"
    ],
    "name": "CVE-2026-28421",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-02-27T22:08:11Z",
    "bugzilla": {
      "description": "vim: Vim: Integrity impact due to stack-buffer-overflow via wide terminal statusline rendering",
      "id": "2443475",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443475"
    },
    "cvss3": {
      "cvss3_base_score": "2.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-135",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl_str_hl()` when rendering a statusline with a multi-byte fill character on a very wide terminal. Version 9.2.0078 patches the issue.",
      "A flaw was found in Vim, an open-source command-line text editor. A local user could exploit a stack-buffer-overflow vulnerability in the `build_stl_str_hl()` function by rendering a statusline with a multi-byte fill character on a very wide terminal. This could lead to an integrity impact, where data might be modified."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28422\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28422\nhttps://github.com/vim/vim/commit/4e5b9e31cb7484ad156f\nhttps://github.com/vim/vim/releases/tag/v9.2.0078\nhttps://github.com/vim/vim/security/advisories/GHSA-gmqx-prf2-8mwf"
    ],
    "name": "CVE-2026-28422",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-09T21:31:36Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Arbitrary code execution or denial of service via maliciously crafted kernel strings",
      "id": "2445901",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445901"
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-120",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow exists in ImageMagick's morphology kernel parsing functions. User-controlled kernel strings exceeding a buffer are copied into fixed-size stack buffers via memcpy without bounds checking, resulting in stack corruption. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick. This vulnerability, a stack buffer overflow, allows an attacker to cause stack corruption by providing maliciously crafted kernel strings. This can lead to arbitrary code execution or a denial of service (DoS), impacting the availability and integrity of the system."
    ],
    "statement": "This is an IMPORTANT vulnerability in ImageMagick, where a stack buffer overflow can occur when processing specially crafted morphology kernel strings. This flaw is triggered when ImageMagick processes user-controlled input containing overly long kernel names or arrays. Red Hat Enterprise Linux systems utilizing ImageMagick are affected if they process untrusted image files.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28494\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28494\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-932h-jw47-73jm"
    ],
    "name": "CVE-2026-28494",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-09T21:33:15Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via heap-buffer-overflow in PCL encode",
      "id": "2445889",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445889"
    },
    "cvss3": {
      "cvss3_base_score": "6.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-131",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, A heap-buffer-overflow vulnerability exists in the PCL encode due to an undersized output buffer allocation. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick, free and open-source software used for editing and manipulating digital images. A local attacker could exploit a heap-buffer-overflow vulnerability in the PCL encode due to an undersized output buffer allocation. This could lead to a denial of service (DoS), making the software unavailable, and potentially impact data integrity."
    ],
    "statement": "This MODERATE impact vulnerability in ImageMagick involves a heap-buffer-overflow within the PCL encoder. Processing a specially crafted image could trigger this flaw, potentially leading to denial of service or other impacts. This affects Red Hat Enterprise Linux 6 ELS and 7 ELS, as well as community projects like Fedora and EPEL, where ImageMagick is used for image processing.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28686\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28686\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-467j-76j7-5885"
    ],
    "name": "CVE-2026-28686",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-09T21:37:24Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Heap use-after-free vulnerability allows denial of service via crafted MSL file",
      "id": "2445897",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445897"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick, free and open-source software used for editing and manipulating digital images. A heap use-after-free vulnerability in ImageMagick's MSL (Magick Scripting Language) decoder allows an attacker to trigger access to freed memory by crafting a malicious MSL file. This can lead to a denial of service."
    ],
    "statement": "MODERATE: This flaw in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by processing a specially crafted MSL file. This could lead to application crashes or potentially arbitrary code execution. Red Hat Enterprise Linux 6 ELS and 7 ELS are affected by this vulnerability.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28687\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28687\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fpvf-frm6-625q"
    ],
    "name": "CVE-2026-28687",
    "mitigation": {
      "value": "To reduce the risk of exploitation, avoid processing untrusted or suspicious MSL files with ImageMagick. Implement strict input validation and ensure that ImageMagick only processes files from trusted sources. If ImageMagick is deployed in a server environment, consider isolating the application within a sandboxed environment to limit potential impact.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-09T21:38:08Z",
    "bugzilla": {
      "description": "ImageMagick: use-after-free in the MSL encoder",
      "id": "2445877",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445877"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-416",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap-use-after-free vulnerability exists in the MSL encoder, where a cloned image is destroyed twice. The MSL coder does not support writing MSL so the write capability has been removed. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick. Processing commands related to MSL writing, specifically cloning an image structure for output, can cause a heap use-after-free vulnerability and result in a denial of service."
    ],
    "statement": "To exploit this issue, an attacker needs to convince a user to process a specially crafted file that makes ImageMagick use the MSL encoder to write or output an image. The malicious file, usually an .msl script or an image designed to invoke MSL processing, will contain instructions to trigger the cloning process and the use-after-free issue, with no evidence it can cause arbitrary command execution. Due to these reasons, this flaw has been rated with a moderate severity.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28688\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28688\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xxw5-m53x-j38c"
    ],
    "name": "CVE-2026-28688",
    "mitigation": {
      "value": "To mitigate this vulnerability, disable the vulnerable encoder by adding the following line to the ImageMagick policy.xml file, typically located in the directory /etc/ImageMagick-7/, /etc/ImageMagick-6/ or /etc/ImageMagick/:\n~~~\n<policy domain=\"coder\" rights=\"none\" pattern=\"MSL\" />\n~~~\nTo reduce the risk of exploitation, avoid processing untrusted MSL files with ImageMagick. If ImageMagick is deployed in a way that it processes files from untrusted sources automatically, consider running the application inside a container or a restricted sandbox environment to limit the potential security impact.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-09T21:39:13Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Information disclosure and unauthorized modification via symlink TOCTOU vulnerability",
      "id": "2445891",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445891"
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "status": "draft"
    },
    "cwe": "CWE-367",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, domain=\"path\" authorization is checked before final file open/use. A symlink swap between check-time and use-time bypasses policy-denied read/write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. A time-of-check to time-of-use (TOCTOU) vulnerability exists where authorization for a file path is checked before the file is finally opened or used. A local attacker can exploit this by performing a symlink swap between the check-time and use-time, bypassing policy-denied read/write operations. This can lead to information disclosure and unauthorized modification of files."
    ],
    "statement": "This MODERATE impact vulnerability in ImageMagick allows a Time-of-Check to Time-of-Use (TOCTOU) symlink race. An attacker could exploit this to bypass path policy restrictions, potentially leading to unauthorized read or write access to files. This affects Red Hat Enterprise Linux and Community Projects that include ImageMagick.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28689\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28689\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-493f-jh8w-qhx3"
    ],
    "name": "CVE-2026-28689",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-09T21:39:53Z",
    "bugzilla": {
      "description": "ImageMagick: stack-based buffer overflow in MNG encoder",
      "id": "2445887",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445887"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-121",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow vulnerability exists in the MNG encoder. There is a bounds checks missing that could corrupting the stack with attacker-controlled data. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick. Processing a specially crafted image with the MNG encoder can cause a stack-based buffer overflow due to a missing bounds check, leading to a denial of service and potentially arbitrary code execution."
    ],
    "statement": "To exploit this issue, an attacker needs to convince a user to process a specially crafted file that makes ImageMagick use the MNG encoder.\nDefault Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability to a denial of service.\nDue to these reasons, this vulnerability has been rated with a moderate severity.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28690\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28690\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7h7q-j33q-hvpf"
    ],
    "name": "CVE-2026-28690",
    "mitigation": {
      "value": "To mitigate this vulnerability, disable the vulnerable encoder by adding the following line to the ImageMagick policy.xml file, typically located in the directory /etc/ImageMagick-7/, /etc/ImageMagick-6/ or /etc/ImageMagick/:\n~~~\n<policy domain=\"coder\" rights=\"none\" pattern=\"MNG\" />\n~~~\nTo reduce the risk of exploitation, avoid processing untrusted MNG files with ImageMagick. If ImageMagick is deployed in a way that it processes files from untrusted sources automatically, consider running the application inside a container or a restricted sandbox environment to limit the potential security impact.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-09T21:40:42Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via uninitialized pointer dereference in JBIG decoder",
      "id": "2445902",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445902"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-824",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an uninitialized pointer dereference vulnerability exists in the JBIG decoder due to a missing check. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick. This vulnerability, an uninitialized pointer dereference, exists in the JBIG decoder due to a missing check. A remote attacker could exploit this by providing a specially crafted image file, leading to a denial of service. This could make the ImageMagick application unavailable to users."
    ],
    "statement": "This is an IMPORTANT vulnerability affecting ImageMagick, present in Red Hat Enterprise Linux 6 ELS and 7 ELS. An uninitialized pointer dereference in the JBIG decoder could lead to a denial of service when processing a specially crafted JBIG image.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6713",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "ImageMagick-0:6.9.10.68-15.el7_9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28691\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28691\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wj8w-pjxf-9g4f"
    ],
    "name": "CVE-2026-28691",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-09T21:41:39Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Information disclosure and denial of service via heap over-read in MAT decoder",
      "id": "2445890",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445890"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MAT decoder uses 32-bit arithmetic due to incorrect parenthesization resulting in a heap over-read. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. A remote attacker could exploit a heap over-read vulnerability in the MAT decoder due to incorrect parenthesization when using 32-bit arithmetic. This could lead to the disclosure of sensitive information and a denial of service (DoS) condition."
    ],
    "statement": "This MODERATE impact vulnerability in ImageMagick stems from a heap buffer over-read within the MAT image decoder due to incorrect 32-bit arithmetic. Red Hat products, including Red Hat Enterprise Linux 6 ELS and 7 ELS, are affected if ImageMagick is used to process specially crafted MAT image files. Exploitation requires processing a malicious MAT image.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28692\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28692\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mrmj-x24c-wwcv"
    ],
    "name": "CVE-2026-28692",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-09T21:42:28Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Out-of-bounds read or write due to integer overflow in DIB coder",
      "id": "2445888",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445888"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. An integer overflow vulnerability in the DIB (Device Independent Bitmap) coder component can be exploited by a remote attacker. By processing a specially crafted image file, this flaw may lead to an out-of-bounds read or write, potentially resulting in arbitrary code execution, privilege escalation, information disclosure, or a Denial of Service (DoS)."
    ],
    "statement": "This is an IMPORTANT vulnerability in ImageMagick where an integer overflow in the DIB image coder can lead to out-of-bounds read or write operations. This flaw could result in arbitrary code execution or denial of service when processing a specially crafted DIB image. Red Hat Enterprise Linux 6 ELS and 7 ELS are affected by this vulnerability.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6713",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "ImageMagick-0:6.9.10.68-15.el7_9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28693\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28693\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hffp-q43q-qq76"
    ],
    "name": "CVE-2026-28693",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-03-24T14:13:26Z",
    "bugzilla": {
      "description": "NGINX: NGINX Plus: NGINX Open Source: NGINX Plus and NGINX Open Source: Request manipulation via header injection in SMTP upstream requests",
      "id": "2450780",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450780"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-93",
    "details": [
      "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in NGINX Plus and NGINX Open Source, specifically within the ngx_mail_smtp_module. This vulnerability allows an attacker-controlled DNS (Domain Name System) server to inject arbitrary headers into SMTP (Simple Mail Transfer Protocol) upstream requests. This is due to the improper handling of Carriage Return (CRLF) sequences in DNS responses. The primary consequence is the potential manipulation of these requests, which could alter their intended behavior."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8346",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nginx-main-1.30.0-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nginx:1.24/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nginx:1.24/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nginx:1.26/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28753\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28753\nhttps://my.f5.com/manage/s/article/K000160367"
    ],
    "name": "CVE-2026-28753",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-05T21:29:41Z",
    "bugzilla": {
      "description": "Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow",
      "id": "2466913",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466913"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.\nIf mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.\nThis issue affects Apache HTTP Server: through 2.4.66.\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.",
      "A flaw was found in mod_proxy_ajp of Apache HTTP Server. This heap-based buffer overflow vulnerability allows a remote attacker, by connecting to a malicious AJP (Apache JServ Protocol) server, to send a specially crafted message. This message can cause mod_proxy_ajp to write attacker-controlled data beyond a heap-based buffer, potentially leading to arbitrary code execution or a denial of service."
    ],
    "affected_release": [
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el7jbcs"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21433",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47046",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "httpd-0:2.4.63-1.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22140",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "httpd:2.4-8100020260519200905.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36846",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "httpd:2.4-8040020260702193120.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36846",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "httpd:2.4-8040020260702193120.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36831",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "httpd:2.4-8060020260702195216.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36831",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "httpd:2.4-8060020260702195216.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36373",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "httpd:2.4-8080020260702200145.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36373",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "httpd:2.4-8080020260702200145.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21391",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.1"
      },
      {
        "product_name": "Red Hat JBoss Core Services 2.4.62.SP4",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27201",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "httpd"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-28780\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-28780\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-28780",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-04T18:05:18Z",
    "bugzilla": {
      "description": "BusyBox: BusyBox: Arbitrary Code Execution via DHCPv6 Client Heap Buffer Overflow",
      "id": "2466526",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466526"
    },
    "cvss3": {
      "cvss3_base_score": "8.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.",
      "A flaw was found in BusyBox. A heap buffer overflow vulnerability exists in the Dynamic Host Configuration Protocol version 6 (DHCPv6) client, specifically within the `option_to_env()` function. Network-adjacent attackers can exploit this by sending a crafted DHCPv6 response containing a malformed D6_OPT_DNS_SERVERS option. This can lead to memory corruption, potentially allowing for arbitrary code execution or denial of service on affected embedded systems lacking heap hardening."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-28T00:00:00Z",
        "advisory": "RHSA-2026:30652",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "busybox-main-1.37.0-7.3.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "busybox",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-29004\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-29004\nhttps://busybox.net/\nhttps://github.com/vda-linux/busybox_mirror/commit/42202bfb1e6ac51fa995beda8be4d7b654aeee2a\nhttps://github.com/vda-linux/busybox_mirror/commit/d368f3f7836d1c2484c8f839316e5c93e76d4409\nhttps://www.vulncheck.com/advisories/busybox-dhcpv6-client-heap-buffer-overflow-via-dns-servers"
    ],
    "name": "CVE-2026-29004",
    "mitigation": {
      "value": "To mitigate this vulnerability, restrict network access to systems running BusyBox as a DHCPv6 client, ensuring that only trusted DHCPv6 servers can communicate with it. If the DHCPv6 client functionality is not essential for the system's operation, consider disabling the `udhcpc6` service or configuring it to only accept responses from known, trusted sources. Consult product-specific documentation for details on managing network services and configurations. Any changes to network service configurations may require a service restart to take effect, potentially impacting network connectivity.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-21T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjacent BSS variables including nfs_server_ip, nfs_server_mount_port, nfs_server_port, nfs_our_port, nfs_state, and rpc_id, potentially achieving memory corruption and control over the NFS client state machine."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-29009\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-29009"
    ],
    "name": "CVE-2026-29009",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-23T21:03:56Z",
    "bugzilla": {
      "description": "systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data",
      "id": "2450505",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450505"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1287",
    "details": [
      "systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.",
      "A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13651",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "systemd-0:257-13.el10_1.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19068",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "systemd-0:257-23.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25900",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "systemd-0:257-9.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50051",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "systemd-0:239-45.el8_4.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50051",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "systemd-0:239-45.el8_4.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50077",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "systemd-0:239-58.el8_6.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50077",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "systemd-0:239-58.el8_6.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50050",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "systemd-0:239-74.el8_8.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50050",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "systemd-0:239-74.el8_8.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13677",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "systemd-0:252-55.el9_7.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19213",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "systemd-0:252-67.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13677",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "systemd-0:252-55.el9_7.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19213",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "systemd-0:252-67.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51277",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "systemd-0:252-14.el9_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51134",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "systemd-0:252-32.el9_4.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49910",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "systemd-0:252-51.el9_6.6"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7299",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "systemd-main-260.1-2.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22634",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1780420428"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14162",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/opentelemetry-collector-rhel9:1778056267"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14162",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/opentelemetry-rhel9-operator:1778056233"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14162",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/opentelemetry-target-allocator-rhel9:1778056245"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1779798159"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1779798164"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Will not fix",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rpm-ostree",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "NetworkManager",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "systemd",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-29111\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-29111\nhttps://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a\nhttps://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6\nhttps://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412\nhttps://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd\nhttps://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f\nhttps://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f\nhttps://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69\nhttps://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6\nhttps://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c\nhttps://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8\nhttps://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764"
    ],
    "name": "CVE-2026-29111",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-08T15:07:59Z",
    "bugzilla": {
      "description": "httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration",
      "id": "2486394",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486394"
    },
    "cvss3": {
      "cvss3_base_score": "4.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
      "A flaw was found in Apache HTTP Server when using the `mod_ldap` module in a per-directory configuration. This use-after-free vulnerability allows a remote attacker to potentially execute arbitrary code or cause a denial of service (DoS) due to improper memory handling. This could lead to system instability or unauthorized control over the affected server."
    ],
    "statement": "CISA's 9.8 is a mechanical worst-case UAF score. Their vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — they're treating it as: \"network-facing service, memory corruption primitive, assume RCE.\" This is how CISA-ADP routinely scores any UAF in a network daemon. They don't analyze actual exploitability; they score the theoretical ceiling of the vulnerability class.\nApache's LOW reflects what actually happens. \n1. Trigger is narrow — mod_ldap must be loaded (not default) AND configured in per-directory context (<Directory>, <Location>, .htaccess). Server-wide LDAP config doesn't trigger it. This is an unusual configuration pattern.\n2. UAF in config merging, not request handling — the freed memory is in the per-directory configuration merge path, which constrains the timing window and what objects occupy the freed allocation. This isn't a heap spray-friendly UAF in a hot request path.\n3. httpd's process model kills RCE reliability — prefork uses separate processes (crash = one child dies, parent respawns), worker/event have per-process address space. Turning a UAF into reliable RCE against httpd is substantially harder than against a single-threaded daemon with a predictable heap layout.\n4. Realistic impact is DoS — the freed pointer will most likely cause a segfault (child crash), not a controlled write primitive. The parent process respawns workers, so even the DoS is transient.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25042",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.68-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Affected",
        "package_name": "jbcs-httpd24-httpd",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Affected",
        "package_name": "mod_ldap.so",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-29167\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-29167\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-29167",
    "mitigation": {
      "value": "upgrade apache web server to 2.4.68",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-05T13:10:05Z",
    "bugzilla": {
      "description": "httpd: mod_md: unrestricted OCSP response leads to resource exhaustion",
      "id": "2466753",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466753"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data.\nThis issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.",
      "A flaw was found in the mod_md module of httpd. When processing OCSP (Online Certificate Status Protocol) responses from a malicious or compromised OCSP responder, the module fails to enforce proper size limits on the incoming data. This issue leads to memory exhaustion and a denial of service."
    ],
    "statement": "To exploit this flaw, the Apache HTTP Server must query an untrusted or compromised OCSP responder, limiting its exposure. Due to this reason, this vulnerability has been rated with a moderate severity.\nThis flaw only affects configurations with mod_md loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.",
    "affected_release": [
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-mod_md-1:2.4.28-16.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el7jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-mod_md-1:2.4.28-16.el7jbcs"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30845",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mod_md-1:2.4.26-5.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52393",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "mod_md-1:2.4.26-3.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30844",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mod_md-1:2.4.26-2.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57642",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "mod_md-1:2.4.19-1.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-21T00:00:00Z",
        "advisory": "RHSA-2026:57844",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "mod_md-1:2.4.19-1.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57641",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "mod_md-1:2.4.26-1.el9_6.2"
      },
      {
        "product_name": "Red Hat JBoss Core Services 2.4.62.SP4",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27201",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "jbcs-httpd24-mod_md"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "httpd:2.4/mod_md",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "mod_md",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-29168\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-29168\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-29168",
    "mitigation": {
      "value": "Disabling mod_md and restarting httpd will mitigate this flaw.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-05-04T14:48:29Z",
    "bugzilla": {
      "description": "httpd: NULL pointer dereference via specially crafted request",
      "id": "2465296",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2465296"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.\nThe only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.\nUsers are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.",
      "A flaw was found in the mod_dav_lock module of httpd. This vulnerability allows a remote unauthenticated attacker to crash the server due to a NULL pointer dereference via a specially crafted request."
    ],
    "statement": "This issue allows an unauthenticated remote attacker to crash the server via a specially crafted request. However, the mod_dav_lock module is obsolete and rarely enabled in modern environments. The only known use-case for the module was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Due to this reason, this vulnerability has been rated with a low severity.\nThis flaw only affects configurations with mod_dav_lock loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.",
    "affected_release": [
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el7jbcs"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34109",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47046",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "httpd-0:2.4.63-1.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42828",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "httpd:2.4-8100020260714175253.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41906",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.5"
      },
      {
        "product_name": "Red Hat JBoss Core Services 2.4.62.SP4",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27201",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "mod_dav_lock.so"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17080",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.67-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-29169\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-29169\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-29169",
    "mitigation": {
      "value": "Disabling mod_dav_lock and restarting httpd will mitigate this flaw.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-08T15:10:09Z",
    "bugzilla": {
      "description": "httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation",
      "id": "2486419",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486419"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-79",
    "details": [
      "A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.\nUsers are recommended to upgrade to version 2.4.68, which fixes this issue.",
      "A flaw was found in Apache HTTP Server, specifically within the `mod_proxy_ftp` module. This cross-site scripting (XSS) vulnerability occurs during the generation of HTML directory lists when the server is configured to list FTP directory contents via either a forward or reverse proxy. An attacker could exploit this by injecting malicious scripts into web pages, which could lead to information disclosure or unauthorized actions when viewed by other users."
    ],
    "statement": "This Moderate impact cross-site scripting (XSS) vulnerability in Apache HTTP Server's `mod_proxy_ftp` module requires specific server configurations to be exploitable. The flaw occurs when `mod_proxy_ftp` is enabled and configured to list FTP directory contents via a proxy, which is not a default setup in Red Hat Enterprise Linux. Successful exploitation depends on a user viewing a specially crafted web page, potentially leading to information disclosure or unauthorized actions within the user's browser context.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25042",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.68-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "httpd:2.4/httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "jbcs-httpd24-httpd",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-29170\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-29170\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-29170",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-13T20:41:50Z",
    "bugzilla": {
      "description": "gstreamer-plugins-base: GStreamer: Arbitrary code execution via RIFF palette integer overflow in AVI file handling",
      "id": "2447496",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447496"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.\nThe specific flaw exists within the handling of palette data in AVI files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28854.",
      "A flaw was found in GStreamer. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. The flaw exists within the handling of palette data in AVI files, where a lack of proper validation of user-supplied data can lead to an integer overflow before writing to memory. An attacker can leverage this integer overflow to execute code in the context of the current process."
    ],
    "statement": "This is an IMPORTANT vulnerability in GStreamer that allows arbitrary code execution. The flaw occurs due to an integer overflow when processing palette data in specially crafted AVI files. Exploitation requires a user to process a malicious AVI file with an application linked against the GStreamer library.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6259",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "gstreamer1-plugins-bad-free-0:1.24.11-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6259",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "gstreamer1-plugins-base-0:1.24.11-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6259",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "gstreamer1-plugins-good-0:1.24.11-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6259",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "gstreamer1-plugins-ugly-free-0:1.24.11-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19024",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19024",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gstreamer1-plugins-base-0:1.26.7-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19024",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gstreamer1-plugins-good-0:1.26.7-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19024",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gstreamer1-plugins-ugly-free-0:1.26.7-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8854",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gstreamer1-plugins-bad-free-0:1.24.11-3.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8854",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gstreamer1-plugins-base-0:1.24.11-1.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8854",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gstreamer1-plugins-good-0:1.24.11-1.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8854",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gstreamer1-plugins-ugly-free-0:1.24.11-1.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7673",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gstreamer1-plugins-bad-free-0:1.10.4-5.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7673",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gstreamer1-plugins-base-0:1.10.4-4.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7673",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gstreamer1-plugins-good-0:1.10.4-4.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7850",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gstreamer-plugins-base-0:0.10.36-11.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7850",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gstreamer-plugins-good-0:0.10.31-14.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6750",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-6.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6750",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gstreamer1-plugins-base-0:1.16.1-6.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6750",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gstreamer1-plugins-good-0:1.16.1-6.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9487",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9487",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "gstreamer1-plugins-base-0:1.16.1-3.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9487",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "gstreamer1-plugins-good-0:1.16.1-3.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9446",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9446",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9446",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gstreamer1-plugins-good-0:1.16.1-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9446",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9446",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9446",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gstreamer1-plugins-good-0:1.16.1-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gstreamer1-plugins-good-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gstreamer1-plugins-good-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gstreamer1-plugins-good-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9488",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9488",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9488",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gstreamer1-plugins-good-0:1.16.1-5.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9488",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9488",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9488",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gstreamer1-plugins-good-0:1.16.1-5.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19180",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-bad-free-0:1.22.12-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19180",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-base-0:1.22.12-8.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19180",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-good-0:1.22.12-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19180",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-ugly-free-0:1.22.12-6.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6300",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-bad-free-0:1.22.12-5.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6300",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-base-0:1.22.12-5.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6300",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-good-0:1.22.12-5.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6300",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-ugly-free-0:1.22.12-4.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8876",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gstreamer1-plugins-bad-free-0:1.18.4-8.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8876",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gstreamer1-plugins-base-0:1.18.4-8.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8876",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gstreamer1-plugins-good-0:1.18.4-7.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8874",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gstreamer1-plugins-bad-free-0:1.18.4-9.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8874",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gstreamer1-plugins-base-0:1.18.4-8.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8874",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gstreamer1-plugins-good-0:1.18.4-8.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8857",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gstreamer1-plugins-bad-free-0:1.22.1-6.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8857",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gstreamer1-plugins-base-0:1.22.1-4.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8857",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gstreamer1-plugins-good-0:1.22.1-4.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8862",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gstreamer1-plugins-bad-free-0:1.22.12-5.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8862",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gstreamer1-plugins-base-0:1.22.12-5.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8862",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gstreamer1-plugins-good-0:1.22.12-5.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8862",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gstreamer1-plugins-ugly-free-0:1.22.12-4.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gstreamer-plugins-base",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "mingw-gstreamer1-plugins-base",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-2921\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2921\nhttps://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/e3a99c35266fc92dd6a18ac5fde028d0cda559e6\nhttps://www.zerodayinitiative.com/advisories/ZDI-26-168/"
    ],
    "name": "CVE-2026-2921",
    "mitigation": {
      "value": "To mitigate this issue, avoid processing untrusted AVI media files with applications that use the GStreamer library. Users should exercise caution when opening or playing AVI files from unknown or suspicious sources.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-13T17:26:58Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP has a heap-buffer-overflow in avc420_yuv_to_rgb via OOB regionRects",
      "id": "2447382",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447382"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap buffer overflow occurs in the FreeRDP client's AVC420/AVC444 YUV-to-RGB conversion path due to missing horizontal bounds validation of H.264 metablock regionRects coordinates.  In yuv.c, the clamp() function (line 347) only validates top/bottom against the surface/YUV height, but never checks left/right against the surface width. When avc420_yuv_to_rgb (line 67) computes destination and source pointers using rect->left, it performs unchecked pointer arithmetic that can reach far beyond the allocated surface buffer. A malicious server sends a WIRE_TO_SURFACE_PDU_1 with AVC420 codec containing a regionRects entry where left greatly exceeds the surface width (e.g., left=60000 on a 128px surface). The H.264 bitstream decodes successfully, then yuv420_process_work_callback calls avc420_yuv_to_rgb which computes pDstPoint = pDstData + rect->top * nDstStep + rect->left * 4, writing 16-byte SSE vectors 1888+ bytes past the allocated heap region. This vulnerability is fixed in 3.24.0.",
      "A heap based buffer overflow flaw has been discovered in FreeRDP. A client-side heap buffer overflow occurs in the FreeRDP client's AVC420/AVC444 YUV-to-RGB conversion path due to missing horizontal bounds validation of H.264 metablock regionRects coordinates. A malicious server can trigger a client-side heap buffer overflow (WRITE of 16 bytes via SSE), causing a crash (DoS) and heap corruption. The attacker controls the offset via the left coordinate, potentially enabling arbitrary write to adjacent heap objects with code-execution risk depending on allocator layout."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-29774\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-29774\nhttps://github.com/FreeRDP/FreeRDP/commit/6482b7a92fff3959582cef052d1967ad6bde3738\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5q35-hv9x-7794"
    ],
    "name": "CVE-2026-29774",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-13T17:28:39Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheId",
      "id": "2447379",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447379"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap out-of-bounds read/write occurs in FreeRDP's bitmap cache subsystem due to an off-by-one boundary check in bitmap_cache_put. A malicious server can send a CACHE_BITMAP_ORDER (Rev1) with cacheId equal to maxCells, bypassing the guard and accessing cells[] one element past the allocated array. This vulnerability is fixed in 3.24.0.",
      "A heap based buffer overflow flaw has been discovered in FreeRDP. This client-side heap out-of-bounds read/write occurs in FreeRDP's bitmap cache subsystem due to an off-by-one boundary check in bitmap_cache_put. A malicious server can send a CACHE_BITMAP_ORDER (Rev1) with cacheId equal to maxCells, bypassing the guard and accessing cells[] one element past the allocated array. A malicious server can trigger a client-side heap out-of-bounds access (READ of 4 bytes, followed by potential WRITE of a pointer) on the bitmap cache cells array, causing a crash (DoS) and heap corruption. The off-by-one accesses cells[maxCells] which reads from and writes to adjacent heap memory, potentially enabling pointer overwrite for code execution depending on heap layout."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16014",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "freerdp-2:3.10.3-5.el10_1.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19142",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freerdp-2:3.10.3-12.el10_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20605",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freerdp-2:3.10.3-3.el10_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20546",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "freerdp-0:2.1.1-5.el7_9.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16019",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "freerdp-2:2.11.7-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16482",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-1.el9_7.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19358",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-7.el9_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16485",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "freerdp-2:2.4.1-3.el9_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16483",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freerdp-2:2.4.1-6.el9_2.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16866",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "freerdp-2:2.11.2-1.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16865",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freerdp-2:2.11.7-1.el9_6.10"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-29775\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-29775\nhttps://github.com/FreeRDP/FreeRDP/commit/ffad58fd2b329efd81a3239e9d7e3c927b8e503f\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h666-rfw3-jhvj"
    ],
    "name": "CVE-2026-29775",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-03-13T17:33:10Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP has an Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library",
      "id": "2447381",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447381"
    },
    "cvss3": {
      "cvss3_base_score": "3.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library This vulnerability is fixed in 3.24.0.",
      "An integer underflow flaw has been discovered in FreeRDP. A uint32 field is populated from a uint16 data element. This field is later modified without proper checks and in some situations a program crash may occur."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-29776\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-29776\nhttps://github.com/FreeRDP/FreeRDP/commit/a9e0abf2eac8c2e370fa155bf1abb9d044c0ca8a\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c747-x4wf-cqrr"
    ],
    "name": "CVE-2026-29776",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-16T00:00:00Z",
    "bugzilla": {
      "description": "fio: fio: Denial of Service via NULL pointer dereference when parsing job files",
      "id": "2458951",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458951"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-476",
    "details": [
      "A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash.",
      "A flaw was found in fio (Flexible I/O Tester). A local user could exploit this vulnerability by providing a specially crafted job file that includes the fdp_pli option without an argument. This leads to a NULL pointer dereference, which occurs when the program attempts to access a memory location that has not been assigned, resulting in a segmentation fault and a Denial of Service (DoS) due to a process crash."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "fio",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "fio",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "fio",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "fio",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-30656\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-30656\nhttps://gist.github.com/Criticayon/eb5e69163bfa4ce684e62ed5c939b76e\nhttps://github.com/axboe/fio/issues/2055"
    ],
    "name": "CVE-2026-30656",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-13T20:39:33Z",
    "bugzilla": {
      "description": "gstreamer-plugins-bad: GStreamer: Remote Code Execution via heap-based buffer overflow in JPEG parser",
      "id": "2447492",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447492"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.\nThe specific flaw exists within the processing of Huffman tables. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28840.",
      "A flaw was found in GStreamer. A remote attacker can exploit a heap-based buffer overflow vulnerability in the GStreamer JPEG parser by providing a specially crafted JPEG file. This issue is caused by improper validation of Huffman table lengths, which can lead to arbitrary code execution in the context of the current process."
    ],
    "statement": "This is an IMPORTANT heap-based buffer overflow vulnerability in the GStreamer JPEG parser. The flaw allows remote code execution when processing a specially crafted JPEG file due to improper validation of Huffman table lengths. Red Hat products utilizing GStreamer to process untrusted JPEG content are affected.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6259",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "gstreamer1-plugins-bad-free-0:1.24.11-3.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6259",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "gstreamer1-plugins-base-0:1.24.11-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6259",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "gstreamer1-plugins-good-0:1.24.11-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6259",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "gstreamer1-plugins-ugly-free-0:1.24.11-2.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19024",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19024",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gstreamer1-plugins-base-0:1.26.7-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19024",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gstreamer1-plugins-good-0:1.26.7-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19024",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gstreamer1-plugins-ugly-free-0:1.26.7-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8854",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gstreamer1-plugins-bad-free-0:1.24.11-3.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8854",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gstreamer1-plugins-base-0:1.24.11-1.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8854",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gstreamer1-plugins-good-0:1.24.11-1.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8854",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gstreamer1-plugins-ugly-free-0:1.24.11-1.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7673",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gstreamer1-plugins-bad-free-0:1.10.4-5.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7673",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gstreamer1-plugins-base-0:1.10.4-4.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7673",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gstreamer1-plugins-good-0:1.10.4-4.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6750",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-6.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6750",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gstreamer1-plugins-base-0:1.16.1-6.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6750",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gstreamer1-plugins-good-0:1.16.1-6.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9487",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9487",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "gstreamer1-plugins-base-0:1.16.1-3.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9487",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "gstreamer1-plugins-good-0:1.16.1-3.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9446",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9446",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9446",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gstreamer1-plugins-good-0:1.16.1-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9446",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9446",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9446",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gstreamer1-plugins-good-0:1.16.1-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gstreamer1-plugins-good-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gstreamer1-plugins-good-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9447",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gstreamer1-plugins-good-0:1.16.1-4.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9488",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9488",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9488",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gstreamer1-plugins-good-0:1.16.1-5.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9488",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gstreamer1-plugins-bad-free-0:1.16.1-4.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9488",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gstreamer1-plugins-base-0:1.16.1-4.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9488",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gstreamer1-plugins-good-0:1.16.1-5.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19180",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-bad-free-0:1.22.12-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19180",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-base-0:1.22.12-8.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19180",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-good-0:1.22.12-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19180",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-ugly-free-0:1.22.12-6.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6300",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-bad-free-0:1.22.12-5.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6300",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-base-0:1.22.12-5.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6300",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-good-0:1.22.12-5.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6300",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gstreamer1-plugins-ugly-free-0:1.22.12-4.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8876",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gstreamer1-plugins-bad-free-0:1.18.4-8.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8876",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gstreamer1-plugins-base-0:1.18.4-8.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8876",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gstreamer1-plugins-good-0:1.18.4-7.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8874",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gstreamer1-plugins-bad-free-0:1.18.4-9.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8874",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gstreamer1-plugins-base-0:1.18.4-8.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8874",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gstreamer1-plugins-good-0:1.18.4-8.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8857",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gstreamer1-plugins-bad-free-0:1.22.1-6.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8857",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gstreamer1-plugins-base-0:1.22.1-4.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8857",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gstreamer1-plugins-good-0:1.22.1-4.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8862",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gstreamer1-plugins-bad-free-0:1.22.12-5.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8862",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gstreamer1-plugins-base-0:1.22.12-5.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8862",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gstreamer1-plugins-good-0:1.22.12-5.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8862",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gstreamer1-plugins-ugly-free-0:1.22.12-4.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gstreamer-plugins-bad-free",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "gstreamer-plugins-bad-free",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "mingw-gstreamer1-plugins-bad-free",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-3082\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-3082\nhttps://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/7d3c258ed928cf59d126c8ea926b185f046f444c\nhttps://www.zerodayinitiative.com/advisories/ZDI-26-163/"
    ],
    "name": "CVE-2026-3082",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-09T21:45:55Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service due to heap overflow when processing large image profiles",
      "id": "2445878",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445878"
    },
    "cvss3": {
      "cvss3_base_score": "5.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-120",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an extremely large image profile could result in a heap overflow when encoding a PNG image. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. A local attacker could exploit this vulnerability by providing an extremely large image profile when encoding a PNG image. This could result in a heap overflow, leading to a Denial of Service (DoS), which makes the affected system or application unavailable to legitimate users."
    ],
    "statement": "This MODERATE impact vulnerability in ImageMagick affects Red Hat Enterprise Linux 6 ELS and 7 ELS. A heap overflow can occur when processing an extremely large image profile during PNG encoding. Exploitation requires an attacker to provide a specially crafted image file for processing.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-30883\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-30883\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qmw5-2p58-xvrc"
    ],
    "name": "CVE-2026-30883",
    "mitigation": {
      "value": "To mitigate this issue, avoid processing untrusted or maliciously crafted image files with ImageMagick. Users should exercise caution when handling image files from unknown or suspicious sources.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-18T02:29:45Z",
    "bugzilla": {
      "description": "pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion",
      "id": "2448553",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448553"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-835",
    "details": [
      "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with \"Indefinite Length\" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.",
      "An unbounded recursion flaw has been discovered in the pypi pyasn1 library. This uncontrolled recursion occurs when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing nested SEQUENCE (0x30) or SET (0x31) tags with Indefinite Length (0x80) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a RecursionError or consumes all available memory (OOM), crashing the host application."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13512",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "python3.12-pyasn1-0:0.6.3-1.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-06-09T00:00:00Z",
        "advisory": "RHSA-2026:24761",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "automation-controller-0:4.6.29-2.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13512",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "python3.12-pyasn1-0:0.6.3-1.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-06-09T00:00:00Z",
        "advisory": "RHSA-2026:24761",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "automation-controller-0:4.6.29-2.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13508",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "python3.12-pyasn1-0:0.6.3-1.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-06-09T00:00:00Z",
        "advisory": "RHSA-2026:24762",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "automation-controller-0:4.7.12-1.el9ap"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13916",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "fence-agents-0:4.16.0-13.el10_1.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19138",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "fence-agents-0:4.16.0-21.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17083",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "fence-agents-0:4.16.0-5.el10_0.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12176",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "fence-agents-0:4.2.1-129.el8_10.25"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13902",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::highavailability",
        "package": "resource-agents-0:4.9.0-54.el8_10.33"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22135",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "fence-agents-0:4.2.1-65.el8_4.28"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22133",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4::highavailability",
        "package": "resource-agents-0:4.1.1-90.el8_4.25"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22135",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "fence-agents-0:4.2.1-65.el8_4.28"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22133",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4::highavailability",
        "package": "resource-agents-0:4.1.1-90.el8_4.25"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22134",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "fence-agents-0:4.2.1-89.el8_6.22"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22134",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "fence-agents-0:4.2.1-89.el8_6.22"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22132",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6::highavailability",
        "package": "resource-agents-0:4.9.0-16.el8_6.22"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22134",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "fence-agents-0:4.2.1-89.el8_6.22"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22132",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6::highavailability",
        "package": "resource-agents-0:4.9.0-16.el8_6.22"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20588",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "fence-agents-0:4.2.1-112.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22131",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8::highavailability",
        "package": "resource-agents-0:4.9.0-40.el8_8.19"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20588",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "fence-agents-0:4.2.1-112.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22131",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8::highavailability",
        "package": "resource-agents-0:4.9.0-40.el8_8.19"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13917",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "fence-agents-0:4.10.0-98.el9_7.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19355",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "fence-agents-0:4.10.0-110.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22987",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "fence-agents-0:4.10.0-43.el9_2.22"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22969",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "fence-agents-0:4.10.0-62.el9_4.25"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:22970",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "fence-agents-0:4.10.0-86.el9_6.17"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16009",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1778244531"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13553",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "ansible-automation-platform-25/ee-supported-rhel8:1777398315"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13553",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "ansible-automation-platform-25/lightspeed-rhel8:1777403872"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13553",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "ansible-automation-platform-25/platform-resource-runner-rhel8:1777402264"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/eda-controller-rhel9:1777296732"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/gateway-rhel9:1777311120"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-rhel9:1777387242"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6309",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-chatbot-rhel9:1774417022"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6404",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-chatbot-rhel9:1774417022"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17611",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-azure-rocm-rhel9:1778677745"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17611",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-rocm-rhel9:1778666124"
      },
      {
        "product_name": "Red Hat Migration Toolkit 1.8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41928",
        "cpe": "cpe:/a:redhat:rhmt:1.8::el8",
        "package": "rhmtc/openshift-migration-hook-runner-rhel8:1783931722"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-kserve-storage-initializer-rhel9:1776343111"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-kserve-storage-initializer-rhel9:1778263407"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1782471672"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1782471731"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:1782471849"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1782471734"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1782471879"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9:1782472374"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9:1782471606"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1782471796"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1782471661"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1782471753"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1782471740"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1782471834"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1782471730"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1782471835"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1782471697"
      },
      {
        "product_name": "Red Hat Quay 3.1",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6912",
        "cpe": "cpe:/a:redhat:quay:3.10::el8",
        "package": "quay/quay-rhel8:1775169155"
      },
      {
        "product_name": "Red Hat Quay 3.12",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6720",
        "cpe": "cpe:/a:redhat:quay:3.12::el8",
        "package": "quay/quay-rhel8:1775253092"
      },
      {
        "product_name": "Red Hat Quay 3.15",
        "release_date": "2026-04-03T00:00:00Z",
        "advisory": "RHSA-2026:6568",
        "cpe": "cpe:/a:redhat:quay:3.15::el8",
        "package": "quay/quay-rhel8:1775169219"
      },
      {
        "product_name": "Red Hat Quay 3.16",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19375",
        "cpe": "cpe:/a:redhat:quay:3.16::el9",
        "package": "quay/quay-rhel9:1779204086"
      },
      {
        "product_name": "Red Hat Quay 3.9",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6926",
        "cpe": "cpe:/a:redhat:quay:3.9::el8",
        "package": "quay/quay-rhel8:1775169218"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.4",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8437",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.4::el9",
        "package": "rhtas/model-transparency-rhel9:1775815407"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14020",
        "cpe": "cpe:/a:redhat:stf:1.5::el9",
        "package": "stf/prometheus-webhook-snmp-rhel9:1777452540"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14020",
        "cpe": "cpe:/a:redhat:stf:1.5::el9",
        "package": "stf/service-telemetry-rhel9-operator:1777407251"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14020",
        "cpe": "cpe:/a:redhat:stf:1.5::el9",
        "package": "stf/smart-gateway-rhel9-operator:1777436150"
      }
    ],
    "package_state": [
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-rhel8-operator",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Will not fix",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Will not fix",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Will not fix",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-training-cuda128-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ztp-site-generate-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/ee-openstack-ansible-ee-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "satellite/iop-insights-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/segment-reporting-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-30922\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-30922\nhttps://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0\nhttps://github.com/pyasn1/pyasn1/security/advisories/GHSA-jr27-m4p2-rc6r"
    ],
    "name": "CVE-2026-30922",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-09T21:46:31Z",
    "bugzilla": {
      "description": "ImageMagick: stack-based buffer overflow in MagnifyImage",
      "id": "2445896",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445896"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-121",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MagnifyImage uses a fixed-size stack buffer. When using a specific image it is possible to overflow this buffer and corrupt the stack. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick. Processing a specially crafted image with the MagnifyImage function can cause a stack-based buffer overflow and memory corruption, leading to a denial of service and potentially arbitrary code execution."
    ],
    "statement": "To exploit this issue, an attacker needs to convince a user to process a specially crafted image.\nDefault Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability to a denial of service.\nDue to these reasons, this vulnerability has been rated with a moderate severity.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-30929\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-30929\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rqq8-jh93-f4vg"
    ],
    "name": "CVE-2026-30929",
    "mitigation": {
      "value": "To reduce the risk of exploitation, avoid processing untrusted images with ImageMagick. If ImageMagick is deployed in a way that it processes files from untrusted sources automatically, consider running the application inside a container or a restricted sandbox environment to limit the potential security impact.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-09T21:49:36Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via crafted image processing",
      "id": "2445880",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445880"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a crafted image could cause an out of bounds heap write inside the WaveletDenoiseImage method. When processing a crafted image with the -wavelet-denoise operation an out of bounds write can occur. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick, a free and open-source software for editing and manipulating digital images. A remote attacker could exploit this vulnerability by providing a specially crafted image to a user, which, when processed with the -wavelet-denoise operation, could lead to an out-of-bounds heap write. This issue can result in a denial of service (DoS), causing the application to become unstable or crash."
    ],
    "statement": "This is a MODERATE impact vulnerability. ImageMagick in Red Hat Enterprise Linux 6 ELS and 7 ELS is affected by a heap buffer overflow. This flaw occurs when processing a specially crafted image using the -wavelet-denoise operation, which could lead to an out-of-bounds write. Exploitation requires user interaction to process the malicious image.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-30936\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-30936\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5ggv-92r5-cp4p"
    ],
    "name": "CVE-2026-30936",
    "mitigation": {
      "value": "To reduce the risk of exploitation, avoid processing untrusted or unverified image files with ImageMagick. Users should exercise caution when handling images from unknown sources. Additionally, consider restricting ImageMagick's capabilities through its policy file to limit exposure to potentially vulnerable operations or file formats.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-09T21:50:15Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via integer overflow in XWD encoder",
      "id": "2445882",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445882"
    },
    "cvss3": {
      "cvss3_base_score": "6.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of bounds heap write can occur. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick, a software suite for editing and manipulating digital images. An integer overflow vulnerability exists in the XWD (X Windows) encoder when processing extremely large images. This flaw can lead to an undersized memory allocation, resulting in an out-of-bounds write to the heap. A local attacker could exploit this to cause a denial of service (DoS) or potentially impact data integrity."
    ],
    "statement": "A MODERATE impact heap buffer overflow exists in ImageMagick's XWD encoder, `WriteXWDImage`. This flaw occurs when processing extremely large images, leading to an undersized heap buffer allocation and a potential out-of-bounds write. Red Hat products shipping ImageMagick are affected if configured to generate or convert excessively large images into the XWD format.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-30937\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-30937\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qpg4-j99f-8xcg"
    ],
    "name": "CVE-2026-30937",
    "mitigation": {
      "value": "To mitigate this issue, restrict ImageMagick's processing of untrusted or excessively large XWD image files. Implement input validation to ensure that image dimensions and sizes are within expected operational limits before processing them with ImageMagick.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-22T00:00:00Z",
    "bugzilla": {
      "description": "kernel: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done()",
      "id": "2460715",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460715"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-1285",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nscsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done()\nA malicious or compromised VIO server can return a num_written value in the\ndiscover targets MAD response that exceeds max_targets. This value is\nstored directly in vhost->num_targets without validation, and is then used\nas the loop bound in ibmvfc_alloc_targets() to index into disc_buf[], which\nis only allocated for max_targets entries. Indices at or beyond max_targets\naccess kernel memory outside the DMA-coherent allocation.  The\nout-of-bounds data is subsequently embedded in Implicit Logout and PLOGI\nMADs that are sent back to the VIO server, leaking kernel memory.\nFix by clamping num_written to max_targets before storing it.",
      "A flaw was found in the Linux kernel's scsi: ibmvfc driver. A malicious or compromised Virtual I/O (VIO) server can exploit this by sending a crafted response during target discovery. This response can cause an out-of-bounds memory access, leading to the disclosure of sensitive kernel memory."
    ],
    "statement": "Red Hat notes this issue is specific to IBM Power virtual Fibre Channel discovery where a hostile VIO server can inflate `num_written` and leak kernel memory embedded into subsequent MADs. Trusted infrastructure assumptions materially affect severity. Fixes arrive through kernel errata; customers not using ibmvfc can avoid loading the driver.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-31464\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-31464\nhttps://lore.kernel.org/linux-cve-announce/2026042252-CVE-2026-31464-f9c5@gregkh/T"
    ],
    "name": "CVE-2026-31464",
    "mitigation": {
      "value": "To mitigate this issue, prevent the ibmvfc module from being loaded. See https://access.redhat.com/solutions/41278 for instructions.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "public_date": "2026-04-24T00:00:00Z",
    "bugzilla": {
      "description": "kernel: ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY",
      "id": "2461484",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461484"
    },
    "cwe": "CWE-364",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY\nfilemap_fault() may drop the mmap_lock before returning VM_FAULT_RETRY,\nas documented in mm/filemap.c:\n\"If our return value has VM_FAULT_RETRY set, it's because the mmap_lock\nmay be dropped before doing I/O or by lock_folio_maybe_drop_mmap().\"\nWhen this happens, a concurrent munmap() can call remove_vma() and free\nthe vm_area_struct via RCU. The saved 'vma' pointer in ocfs2_fault() then\nbecomes a dangling pointer, and the subsequent trace_ocfs2_fault() call\ndereferences it -- a use-after-free.\nFix this by saving ip_blkno as a plain integer before calling\nfilemap_fault(), and removing vma from the trace event. Since\nip_blkno is copied by value before the lock can be dropped, it\nremains valid regardless of what happens to the vma or inode\nafterward.",
      "A flaw was found in the Linux kernel's OCFS2 (Oracle Cluster File System version 2) component. A local attacker could exploit a use-after-free vulnerability when `filemap_fault()` drops the `mmap_lock` before returning `VM_FAULT_RETRY`. This allows a concurrent `munmap()` operation to free a `vm_area_struct`, leading to `ocfs2_fault()` dereferencing a dangling pointer. This issue can result in system instability or crashes."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-31597\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-31597\nhttps://lore.kernel.org/linux-cve-announce/2026042417-CVE-2026-31597-79cd@gregkh/T"
    ],
    "name": "CVE-2026-31597",
    "csaw": false
  },
  {
    "public_date": "2026-04-24T00:00:00Z",
    "bugzilla": {
      "description": "kernel: ocfs2: fix possible deadlock between unlink and dio_end_io_write",
      "id": "2461441",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461441"
    },
    "cwe": "CWE-833",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nocfs2: fix possible deadlock between unlink and dio_end_io_write\nocfs2_unlink takes orphan dir inode_lock first and then ip_alloc_sem,\nwhile in ocfs2_dio_end_io_write, it acquires these locks in reverse order.\nThis creates an ABBA lock ordering violation on lock classes\nocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE] and\nocfs2_file_ip_alloc_sem_key.\nLock Chain #0 (orphan dir inode_lock -> ip_alloc_sem):\nocfs2_unlink\nocfs2_prepare_orphan_dir\nocfs2_lookup_lock_orphan_dir\ninode_lock(orphan_dir_inode) <- lock A\n__ocfs2_prepare_orphan_dir\nocfs2_prepare_dir_for_insert\nocfs2_extend_dir\nocfs2_expand_inline_dir\ndown_write(&oi->ip_alloc_sem) <- Lock B\nLock Chain #1 (ip_alloc_sem -> orphan dir inode_lock):\nocfs2_dio_end_io_write\ndown_write(&oi->ip_alloc_sem) <- Lock B\nocfs2_del_inode_from_orphan()\ninode_lock(orphan_dir_inode) <- Lock A\nDeadlock Scenario:\nCPU0 (unlink)                     CPU1 (dio_end_io_write)\n------                            ------\ninode_lock(orphan_dir_inode)\ndown_write(ip_alloc_sem)\ndown_write(ip_alloc_sem)\ninode_lock(orphan_dir_inode)\nSince ip_alloc_sem is to protect allocation changes, which is unrelated\nwith operations in ocfs2_del_inode_from_orphan.  So move\nocfs2_del_inode_from_orphan out of ip_alloc_sem to fix the deadlock.",
      "A flaw was found in the ocfs2 file system within the Linux kernel. A local user could potentially trigger a deadlock due to an ABBA lock ordering violation between the `ocfs2_unlink` and `ocfs2_dio_end_io_write` functions. This race condition, caused by inconsistent lock acquisition order, could lead to a system hang, resulting in a Denial of Service (DoS)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-31598\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-31598\nhttps://lore.kernel.org/linux-cve-announce/2026042417-CVE-2026-31598-6408@gregkh/T"
    ],
    "name": "CVE-2026-31598",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-24T00:00:00Z",
    "bugzilla": {
      "description": "kernel: usbip: validate number_of_packets in usbip_pack_ret_submit()",
      "id": "2461521",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461521"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-805",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nusbip: validate number_of_packets in usbip_pack_ret_submit()\nWhen a USB/IP client receives a RET_SUBMIT response,\nusbip_pack_ret_submit() unconditionally overwrites\nurb->number_of_packets from the network PDU. This value is\nsubsequently used as the loop bound in usbip_recv_iso() and\nusbip_pad_iso() to iterate over urb->iso_frame_desc[], a flexible\narray whose size was fixed at URB allocation time based on the\n*original* number_of_packets from the CMD_SUBMIT.\nA malicious USB/IP server can set number_of_packets in the response\nto a value larger than what was originally submitted, causing a heap\nout-of-bounds write when usbip_recv_iso() writes to\nurb->iso_frame_desc[i] beyond the allocated region.\nKASAN confirmed this with kernel 7.0.0-rc5:\nBUG: KASAN: slab-out-of-bounds in usbip_recv_iso+0x46a/0x640\nWrite of size 4 at addr ffff888106351d40 by task vhci_rx/69\nThe buggy address is located 0 bytes to the right of\nallocated 320-byte region [ffff888106351c00, ffff888106351d40)\nThe server side (stub_rx.c) and gadget side (vudc_rx.c) already\nvalidate number_of_packets in the CMD_SUBMIT path since commits\nc6688ef9f297 (\"usbip: fix stub_rx: harden CMD_SUBMIT path to handle\nmalicious input\") and b78d830f0049 (\"usbip: fix vudc_rx: harden\nCMD_SUBMIT path to handle malicious input\"). The server side validates\nagainst USBIP_MAX_ISO_PACKETS because no URB exists yet at that point.\nOn the client side we have the original URB, so we can use the tighter\nbound: the response must not exceed the original number_of_packets.\nThis mirrors the existing validation of actual_length against\ntransfer_buffer_length in usbip_recv_xbuff(), which checks the\nresponse value against the original allocation size.\nKelvin Mbogo's series (\"usb: usbip: fix integer overflow in\nusbip_recv_iso()\", v2) hardens the receive-side functions themselves;\nthis patch complements that work by catching the bad value at its\nsource -- in usbip_pack_ret_submit() before the overwrite -- and\nusing the tighter per-URB allocation bound rather than the global\nUSBIP_MAX_ISO_PACKETS limit.\nFix this by checking rpdu->number_of_packets against\nurb->number_of_packets in usbip_pack_ret_submit() before the\noverwrite. On violation, clamp to zero so that usbip_recv_iso() and\nusbip_pad_iso() safely return early.",
      "A flaw was found in the Linux kernel's USB/IP subsystem. A malicious USB/IP server could exploit a vulnerability in the `usbip_pack_ret_submit()` function by sending a specially crafted `RET_SUBMIT` response. This response, containing an oversized `number_of_packets` value, could cause a heap out-of-bounds write. This issue may lead to a denial of service or potentially arbitrary code execution on the client system."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19569",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "kernel-0:6.12.0-211.16.1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24343",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "kernel-0:6.12.0-55.77.1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-17T00:00:00Z",
        "advisory": "RHSA-2026:41236",
        "cpe": "cpe:/a:redhat:rhel_extras_rt_els:7",
        "package": "kernel-rt-0:3.10.0-1160.155.1.rt56.1307.el7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25095",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "kernel-0:3.10.0-1160.151.1.el7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19568",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "kernel-0:5.14.0-687.10.1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19568",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "kernel-0:5.14.0-687.10.1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23224",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "kernel-0:5.14.0-570.119.1.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-31607\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-31607\nhttps://lore.kernel.org/linux-cve-announce/2026042420-CVE-2026-31607-7bac@gregkh/T"
    ],
    "name": "CVE-2026-31607",
    "mitigation": {
      "value": "To mitigate this vulnerability, prevent the `usbip` kernel module from loading by blacklisting it. Create a file named `/etc/modprobe.d/blacklist-usbip.conf` with the following content:\n```\nblacklist usbip\n```\nAfter creating the file, regenerate the initramfs and reboot the system for the changes to take effect. This may impact functionality that relies on USB/IP.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "public_date": "2026-04-24T00:00:00Z",
    "bugzilla": {
      "description": "kernel: fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO",
      "id": "2461563",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461563"
    },
    "cwe": "CWE-369",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nfbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO\nMuch like commit 19f953e74356 (\"fbdev: fb_pm2fb: Avoid potential divide\nby zero error\"), we also need to prevent that same crash from happening\nin the udlfb driver as it uses pixclock directly when dividing, which\nwill crash.",
      "A flaw was found in the Linux kernel's fbdev subsystem, specifically affecting the tdfxfb and udlfb drivers. This vulnerability allows a local attacker to trigger a divide-by-zero error when performing the FBIOPUT_VSCREENINFO operation. This can lead to a system crash, resulting in a Denial of Service (DoS) for the affected system."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-31618\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-31618\nhttps://lore.kernel.org/linux-cve-announce/2026042424-CVE-2026-31618-baf8@gregkh/T"
    ],
    "name": "CVE-2026-31618",
    "csaw": false
  },
  {
    "public_date": "2026-04-24T00:00:00Z",
    "bugzilla": {
      "description": "kernel: NFC: digital: Bounds check NFC-A cascade depth in SDD response handler",
      "id": "2461459",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461459"
    },
    "cwe": "CWE-120",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nNFC: digital: Bounds check NFC-A cascade depth in SDD response handler\nThe NFC-A anti-collision cascade in digital_in_recv_sdd_res() appends 3\nor 4 bytes to target->nfcid1 on each round, but the number of cascade\nrounds is controlled entirely by the peer device.  The peer sets the\ncascade tag in the SDD_RES (deciding 3 vs 4 bytes) and the\ncascade-incomplete bit in the SEL_RES (deciding whether another round\nfollows).\nISO 14443-3 limits NFC-A to three cascade levels and target->nfcid1 is\nsized accordingly (NFC_NFCID1_MAXSIZE = 10), but nothing in the driver\nactually enforces this.  This means a malicious peer can keep the\ncascade running, writing past the heap-allocated nfc_target with each\nround.\nFix this by rejecting the response when the accumulated UID would exceed\nthe buffer.\nCommit e329e71013c9 (\"NFC: nci: Bounds check struct nfc_target arrays\")\nfixed similar missing checks against the same field on the NCI path.",
      "A flaw was found in the Linux kernel's NFC (Near Field Communication) digital subsystem. A malicious peer device can exploit this vulnerability by sending specially crafted NFC-A anti-collision cascade responses. This allows the peer to exceed the intended cascade depth, leading to a heap overflow by writing past the allocated buffer for the nfc_target. This memory corruption can result in a denial of service or potentially arbitrary code execution."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-31622\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-31622\nhttps://lore.kernel.org/linux-cve-announce/2026042426-CVE-2026-31622-dc00@gregkh/T"
    ],
    "name": "CVE-2026-31622",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-13T17:40:19Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP: Arbitrary code execution via crafted Remote Desktop Protocol (RDP) server messages",
      "id": "2447376",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447376"
    },
    "cvss3": {
      "cvss3_base_score": "8.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0,  the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height values provided by the server are not properly validated against the actual desktop dimensions. A malicious RDP server can supply crafted bmp.width and bmp.height values that exceed the expected surface size. Because these values are used during bitmap decoding and memory operations without proper bounds checking, this can lead to a heap buffer overflow. Since the attacker can also control the associated pixel data transmitted by the server, the overflow may be exploitable to overwrite adjacent heap memory. This vulnerability is fixed in 3.24.0.",
      "A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP). The `gdi_surface_bits()` function, which processes `SURFACE_BITS_COMMAND` messages, does not properly validate image dimensions (`bmp.width` and `bmp.height`) provided by a malicious RDP server. This can lead to a heap buffer overflow during bitmap decoding and memory operations. A remote attacker could exploit this to overwrite adjacent memory, potentially resulting in arbitrary code execution."
    ],
    "statement": "For this vulnerability to be exploited, a susceptible system must connect to a malicious server. For that reason, Red Hat recommends that you only use FreeRDP to connect to trusted servers.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6799",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "freerdp-2:3.10.3-5.el10_1.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19033",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freerdp-2:3.10.3-12.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6743",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freerdp-2:3.10.3-3.el10_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11323",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "freerdp-0:2.1.1-5.el7_9.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6918",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "freerdp-2:2.11.7-6.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10734",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "freerdp-2:2.0.0-46.rc4.el8_2.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10735",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "freerdp-2:2.2.0-12.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10735",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "freerdp-2:2.2.0-12.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10951",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10951",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10951",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10076",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10076",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-01T00:00:00Z",
        "advisory": "RHSA-2026:6340",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-1.el9_7.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9640",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "freerdp-2:2.4.1-3.el9_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9641",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freerdp-2:2.4.1-6.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:6958",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "freerdp-2:2.11.2-1.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6727",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freerdp-2:2.11.7-1.el9_6.7"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-31806\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-31806\nhttps://github.com/FreeRDP/FreeRDP/commit/83d9aedea278a74af3e490ff5eeb889c016dbb2b\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rrqm-46rj-cmx2"
    ],
    "name": "CVE-2026-31806",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-02-25T04:04:00Z",
    "bugzilla": {
      "description": "util-linux: util-linux: Access control bypass due to improper hostname canonicalization",
      "id": "2442570",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2442570"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-289",
    "details": [
      "A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.",
      "A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."
    ],
    "statement": "This issue was rated as a Low severity issue. This is an authorization policy bypass limited to host-based access control decisions. It does not bypass authentication or grant elevated privileges. Exploitation is configuration-dependent and primarily affects legacy or uncommon remote login pathways, but it can violate administrator intent and weaken PAM-based security policy enforcement.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7180",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "util-linux-main-2.42-7.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "util-linux",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "util-linux",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "util-linux",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "util-linux",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-3184\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-3184"
    ],
    "name": "CVE-2026-3184",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-13T17:35:17Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP: Denial of Service via crafted audio data in RDP",
      "id": "2447386",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447386"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-191",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM and MS-ADPCM audio decoders leads to heap-buffer-overflow write via the RDPSND audio channel. In libfreerdp/codec/dsp.c, the IMA-ADPCM and MS-ADPCM decoders subtract block header sizes from a size_t variable without checking for underflow. When nBlockAlign (received from the server) is set such that size % block_size == 0 triggers the header parsing at a point where size is smaller than the header (4 or 8 bytes), the subtraction wraps size to ~SIZE_MAX. The while (size > 0) loop then continues for an astronomical number of iterations. This vulnerability is fixed in 3.24.0.",
      "A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP). A remote attacker can exploit a size_t underflow vulnerability in the IMA-ADPCM and MS-ADPCM audio decoders by sending specially crafted audio data over the RDPSND audio channel. This underflow leads to a heap-buffer-overflow write, which can result in a denial of service for the FreeRDP client."
    ],
    "statement": "Red Hat has protection mechanisms in place, such as FORTIFY_SOURCE, Position Independent Executables or Stack Smashing Protection.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16014",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "freerdp-2:3.10.3-5.el10_1.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19142",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freerdp-2:3.10.3-12.el10_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20605",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freerdp-2:3.10.3-3.el10_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20546",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "freerdp-0:2.1.1-5.el7_9.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16019",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "freerdp-2:2.11.7-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16482",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-1.el9_7.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19358",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-7.el9_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16485",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "freerdp-2:2.4.1-3.el9_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16483",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freerdp-2:2.4.1-6.el9_2.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16866",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "freerdp-2:2.11.2-1.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16865",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freerdp-2:2.11.7-1.el9_6.10"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-31883\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-31883\nhttps://github.com/FreeRDP/FreeRDP/commit/16df2300e1e3f5a51f68fb1626429e58b531b7c8\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-85x9-4xxp-xhm5"
    ],
    "name": "CVE-2026-31883",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-13T17:36:57Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP has a division-by-zero in ADPCM decoders when `nBlockAlign` is 0",
      "id": "2447385",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447385"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-369",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, division by zero in MS-ADPCM and IMA-ADPCM decoders when nBlockAlign is 0, leading to a crash. In libfreerdp/codec/dsp.c, both ADPCM decoders use size % block_size where block_size = context->common.format.nBlockAlign. The nBlockAlign value comes from the Server Audio Formats PDU on the RDPSND channel. The value 0 is not validated anywhere before reaching the decoder. When nBlockAlign = 0, the modulo operation causes a SIGFPE (floating point exception) crash. This vulnerability is fixed in 3.24.0.",
      "A division by zero flaw has been discovered in FreeRDP. This division by zero exists in the MS-ADPCM and IMA-ADPCM decoders when nBlockAlign is 0, leading to a crash. In libfreerdp/codec/dsp.c, both ADPCM decoders use size % block_size where block_size = context->common.format.nBlockAlign. The nBlockAlign value comes from the Server Audio Formats PDU on the RDPSND channel. The value 0 is not validated anywhere before reaching the decoder. When nBlockAlign = 0, the modulo operation causes a SIGFPE (floating point exception) crash."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16014",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "freerdp-2:3.10.3-5.el10_1.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19142",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freerdp-2:3.10.3-12.el10_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20605",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freerdp-2:3.10.3-3.el10_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20546",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "freerdp-0:2.1.1-5.el7_9.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16019",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "freerdp-2:2.11.7-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16482",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-1.el9_7.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19358",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-7.el9_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16485",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "freerdp-2:2.4.1-3.el9_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16483",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freerdp-2:2.4.1-6.el9_2.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16866",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "freerdp-2:2.11.2-1.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16865",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freerdp-2:2.11.7-1.el9_6.10"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-31884\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-31884\nhttps://github.com/FreeRDP/FreeRDP/commit/03b48b3601d867afccac1cdc6081de7a275edce7\nhttps://github.com/FreeRDP/FreeRDP/commit/16df2300e1e3f5a51f68fb1626429e58b531b7c8\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jp7m-94ww-p56r"
    ],
    "name": "CVE-2026-31884",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-13T17:38:23Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checks",
      "id": "2447383",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447383"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-ADPCM and IMA-ADPCM decoders due to unchecked predictor and step_index values from input data. This vulnerability is fixed in 3.24.0.",
      "An out of bounds read flaw has been discovered in FreeRDP. This out-of-bounds read exists in the MS-ADPCM and IMA-ADPCM decoders due to unchecked predictor and step_index values from input data. An attacker may be able to leverage this weakness to leak global data."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16014",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "freerdp-2:3.10.3-5.el10_1.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19142",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freerdp-2:3.10.3-12.el10_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20605",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freerdp-2:3.10.3-3.el10_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20546",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "freerdp-0:2.1.1-5.el7_9.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16019",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "freerdp-2:2.11.7-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16482",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-1.el9_7.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19358",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-7.el9_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16485",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "freerdp-2:2.4.1-3.el9_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16483",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freerdp-2:2.4.1-6.el9_2.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16866",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "freerdp-2:2.11.2-1.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16865",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freerdp-2:2.11.7-1.el9_6.10"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-31885\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-31885\nhttps://github.com/FreeRDP/FreeRDP/commit/16df2300e1e3f5a51f68fb1626429e58b531b7c8\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h23r-3988-3wf3"
    ],
    "name": "CVE-2026-31885",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-03-13T17:42:11Z",
    "bugzilla": {
      "description": "freerdp: FreeRDP has an out-of-bounds read in `freerdp_bitmap_decompress_planar`",
      "id": "2447380",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447380"
    },
    "cvss3": {
      "cvss3_base_score": "3.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in freerdp_bitmap_decompress_planar when SrcSize is 0. The function dereferences *srcp (which points to pSrcData) without first verifying that SrcSize >= 1. When SrcSize is 0 and pSrcData is non-NULL, this reads one byte past the end of the source buffer. This vulnerability is fixed in 3.24.0.",
      "An out of bounds read flaw has been discovered in FreeRDP. This Out-of-bounds read exists in the `freerdp_bitmap_decompress_planar` function when SrcSize is 0. This flaw may allow an attcker to read of 1 byte from heap memory in some situation. The more common and expected impact is a crash when the read hits an unmapped page."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-31897\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-31897\nhttps://github.com/FreeRDP/FreeRDP/commit/cd27c8faca0eeb0d4309cc5837dfdf3c42eba4e7\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-xgv6-r22m-7c9x"
    ],
    "name": "CVE-2026-31897",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-11T19:27:23Z",
    "bugzilla": {
      "description": "tornado-python: Tornado: Denial of Service via large multipart bodies",
      "id": "2446765",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446765"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.",
      "A flaw was found in tornado-python. A remote attacker can exploit this vulnerability by sending a specially crafted, very large multipart body with numerous parts. Because the parsing of these large bodies occurs synchronously on the main thread, it can consume excessive resources, leading to a denial of service (DoS) for the application."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13641",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "python-tornado-0:6.5.5-1.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19034",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "python-tornado-0:6.5.5-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20577",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "python-tornado-0:6.4.2-1.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24342",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "python-tornado-0:4.2.1-5.el7_9.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8093",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::highavailability",
        "package": "pcs-0:0.10.18-2.el8_10.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11493",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4::highavailability",
        "package": "pcs-0:0.10.8-1.el8_4.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11493",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4::highavailability",
        "package": "pcs-0:0.10.8-1.el8_4.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11494",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6::highavailability",
        "package": "pcs-0:0.10.12-6.el8_6.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11494",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6::highavailability",
        "package": "pcs-0:0.10.12-6.el8_6.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11495",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8::highavailability",
        "package": "pcs-0:0.10.15-4.el8_8.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11495",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8::highavailability",
        "package": "pcs-0:0.10.15-4.el8_8.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13670",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python-tornado-0:6.5.5-1.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19189",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python-tornado-0:6.5.5-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11454",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0::highavailability",
        "package": "pcs-0:0.11.1-10.el9_0.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20573",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "python-tornado-0:6.4.2-1.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20810",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python-tornado-0:6.4.2-1.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20572",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "python-tornado-0:6.4.2-2.el9_6.3"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-llama-stack-core-rhel9:1775144403"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1780078312"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9:1780069491"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1780078429"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1780069222"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:1780078632"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1780078416"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1780417775"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1780078388"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1780069146"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9:1780069205"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9:1780069224"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9:1780069470"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1780078413"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1780069226"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1780078629"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1780078414"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1780078632"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1780069222"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-llama-stack-core-rhel9:1782471587"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1782471672"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9:1782471678"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1782471731"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1782471732"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:1782471849"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1782471734"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1782471879"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9:1782471606"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1782471796"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1782471661"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9:1782471672"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9:1782471731"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9:1782471929"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1782471753"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1782471740"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1782471834"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1782471730"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1782471835"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1782471697"
      }
    ],
    "package_state": [
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/bitwarden-sdk-server-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-operator-bundle",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-operator-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Affected",
        "package_name": "lightspeed-core/lightspeed-stack-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Affected",
        "package_name": "lightspeed-core/rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "pcs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/disk-image-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-ragas-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "python-pep517",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "python-tornado",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-31958\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-31958\nhttps://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc"
    ],
    "name": "CVE-2026-31958",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-20T14:55:38Z",
    "bugzilla": {
      "description": "pip: pip: Incorrect file installation due to improper archive handling",
      "id": "2459774",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459774"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-1287",
    "details": [
      "pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.",
      "A flaw was found in pip. This vulnerability occurs because pip incorrectly processes concatenated tar and ZIP files as ZIP files, regardless of their true format. This improper handling can lead to confusing installation behavior, potentially causing the installation of unintended or 'incorrect' files. This could allow an attacker to influence the installation process by providing a specially crafted archive."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-21T00:00:00Z",
        "advisory": "RHSA-2026:20074",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python-pip-main-26.1.1-3.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36359",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python-pip-main-26.1.2-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Fix deferred",
        "package_name": "lightspeed-core/lightspeed-stack-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Fix deferred",
        "package_name": "lightspeed-core/rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Fix deferred",
        "package_name": "mta/mta-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Fix deferred",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Out of support scope",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:0"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii-preview/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform-24/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform-25/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Fix deferred",
        "package_name": "rhdh/rhdh-hub-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhel10/python-312-minimal",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "ubi10/python-312-minimal",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "ubi8/python-311",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "ubi8/python-312",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "ubi8/python-36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "ubi8/python-39",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/python-311",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/python-39",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "ubi9/python-311",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "ubi9/python-312",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "ubi9/python-312-minimal",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "ubi9/python-39",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/disk-image-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-cuda-12.9-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-cuda-13.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-neuron-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-rocm-6.4-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-rocm-7.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-spyre-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-tpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-built-in-detector-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-nlp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-tgis-serving-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-guardrails-detector-huggingface-runtime-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlserver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ta-lmes-job-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda121-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda124-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda128-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda128-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/udi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Out of support scope",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Out of support scope",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/foreman-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Fix deferred",
        "package_name": "rhtas/model-transparency-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Out of support scope",
        "package_name": "rhtas/segment-reporting-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Fix deferred",
        "package_name": "stf/prometheus-webhook-snmp-rhel9",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Fix deferred",
        "package_name": "stf/service-telemetry-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Fix deferred",
        "package_name": "stf/smart-gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-3219\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-3219\nhttps://github.com/pypa/pip/pull/13870\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ/"
    ],
    "name": "CVE-2026-3219",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-12T19:38:12Z",
    "bugzilla": {
      "description": "ImageMagick: stack-based buffer overflow in sixel encoder",
      "id": "2447112",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447112"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-121",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, when a memory allocation fails in the sixel encoder it would be possible to write past the end of a buffer on the stack. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.",
      "A flaw was found in ImageMagick. Processing a specially crafted file with the sixel encoder can cause a stack-based buffer overflow when a memory allocation fails, leading to a denial of service."
    ],
    "statement": "To exploit this issue, an attacker needs to convince a user to process a specially crafted file that makes ImageMagick use the sixel encoder. Furthermore, this flaw is only triggered when a memory allocation fails, limiting the possibility of exploitation even further.\nDefault Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability to a denial of service.\nDue to these reasons, this vulnerability has been rated with a moderate severity.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-32259\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-32259\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-49hx-7656-jpg3"
    ],
    "name": "CVE-2026-32259",
    "mitigation": {
      "value": "To mitigate this vulnerability, disable the vulnerable encoder by adding the following line to the ImageMagick policy.xml file, typically located in the directory /etc/ImageMagick-7/, /etc/ImageMagick-6/ or /etc/ImageMagick/:\n~~~\n<policy domain=\"coder\" rights=\"none\" pattern=\"sixel\" />\n~~~\nTo reduce the risk of exploitation, avoid processing sixel files from untrusted sources. If ImageMagick is deployed in a way that it processes files from untrusted sources automatically, consider running the application inside a container or a restricted sandbox environment to limit the potential security impact.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-08T01:06:57Z",
    "bugzilla": {
      "description": "archive/tar: golang: Go's archive/tar package: Denial of Service via maliciously-crafted archive",
      "id": "2456332",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456332"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format.",
      "A flaw was found in Go's `archive/tar` package. A remote attacker could exploit this vulnerability by providing a maliciously-crafted archive file. When the `tar.Reader` processes an archive containing a large number of sparse regions in the \"old GNU sparse map\" format, it can lead to unbounded memory allocation. This can result in a Denial of Service (DoS) condition, making the affected application unresponsive."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7291",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-26-main-1.26.2-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7385",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "golang1-25-main-1.25.9-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/assisted-installer-ds-main",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Builds for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/openshift-builds-waiter-1-6",
        "cpe": "cpe:/a:redhat:openshift_builds:1"
      },
      {
        "product_name": "Builds for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/openshift-builds-waiter-1-7",
        "cpe": "cpe:/a:redhat:openshift_builds:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/jetstack-cert-manager-1-17",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/jetstack-cert-manager-1-18",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/osc-caa",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Cryostat 4",
        "fix_state": "Fix deferred",
        "package_name": "cryostat/cryostat-storage-rhel9",
        "cpe": "cpe:/a:redhat:cryostat:4"
      },
      {
        "product_name": "Custom Metric Autoscaler operator for Red Hat Openshift",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/keda-adapter",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
      },
      {
        "product_name": "Deployment Validation Operator",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/deployment-validation-operator",
        "cpe": "cpe:/a:redhat:deployment_validator_operator"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/art-images",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/logging-loki-v6-0",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/logging-loki-v6-2",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/logging-loki-v6-4",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Fix deferred",
        "package_name": "mta/mta-cli-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/art-images",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/art-images",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/backplane-operator-mce-210",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/backplane-operator-mce-211",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/backplane-operator-mce-26",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/backplane-operator-mce-27",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/backplane-operator-mce-28",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/backplane-operator-mce-29",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Fix deferred",
        "package_name": "multicluster-globalhub/multicluster-globalhub-agent-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Fix deferred",
        "package_name": "multicluster-globalhub/multicluster-globalhub-agent-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Fix deferred",
        "package_name": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/flowlogs-pipeline-zstream",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/art-images",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Fix deferred",
        "package_name": "helm",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/openshift-mcp-server",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Fix deferred",
        "package_name": "openshift-pipelines-client",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-clients",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/kn-plugin-event-sender",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/ossm-2-6-cni",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/ossm-3-0-cni",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/ossm-3-1-cni",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/ossm-3-2-cni",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/ossm-3-3-cni",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Source-to-Image (S2I)",
        "fix_state": "Fix deferred",
        "package_name": "source-to-image/source-to-image-rhel8",
        "cpe": "cpe:/a:redhat:source_to_image:1"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/volsync-0-13",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/volsync-0-14",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/volsync-0-15",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Fix deferred",
        "package_name": "rhacs-eng/release-main",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Fix deferred",
        "package_name": "rhceph-ci/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Fix deferred",
        "package_name": "rhceph-ci/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Certification Program for Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "redhat-certification-preflight",
        "cpe": "cpe:/a:redhat:certifications:9"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/rhcl-1-3-authorino",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Fix deferred",
        "package_name": "flightctl",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/flightctl-api",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "golang",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "osbuild-composer",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/bootc-image-builder-10-0",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/bootc-image-builder-10-1",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "container-tools:rhel8/buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "container-tools:rhel8/conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "container-tools:rhel8/podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "container-tools:rhel8/skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "go-toolset:rhel8/golang",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "go-toolset:rhel8/go-toolset",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "osbuild-composer",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "weldr-client",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "golang",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "go-toolset",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "osbuild-composer",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/bootc-image-builder-9-6",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "redhat-user-workloads/bootc-image-builder-9-7",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "weldr-client",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "golang",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trainer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "conmon",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "cri-o",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "microshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-installer",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-tools-rhel7",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift-clients",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "podman",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/art-images",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "skopeo",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Fix deferred",
        "package_name": "ocs4/cephcsi-rhel8",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Fix deferred",
        "package_name": "odf4/cephcsi-rhel8",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Fix deferred",
        "package_name": "odf4/cephcsi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Fix deferred",
        "package_name": "rhceph-dev/odf4-cephcsi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/udi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/tempo",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/windows-machine-config-operator-release-4-21",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/dex-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/dex-rhel9",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Fix deferred",
        "package_name": "cnv-tech-preview/virt-api",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Fix deferred",
        "package_name": "container-native-virtualization/virt-api",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Fix deferred",
        "package_name": "container-native-virtualization/virt-api-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Fix deferred",
        "package_name": "kubevirt",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift-golang-builder-container",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/osp-director-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/osp-director-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso-operators/openstack-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/quay-quay-v3-10",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/quay-quay-v3-12",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/quay-quay-v3-13",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/quay-quay-v3-14",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/quay-quay-v3-15",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/quay-quay-v3-16",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/quay-quay-v3-17",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/quay-quay-v3-9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Service Interconnect 1",
        "fix_state": "Fix deferred",
        "package_name": "skupper-cli",
        "cpe": "cpe:/a:redhat:service_interconnect:1"
      },
      {
        "product_name": "Red Hat Service Interconnect 2",
        "fix_state": "Fix deferred",
        "package_name": "skupper-cli",
        "cpe": "cpe:/a:redhat:service_interconnect:2"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/cli-v08",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Fix deferred",
        "package_name": "securesign/gitsign",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Security Profiles Operator",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/security-profiles-operator-release",
        "cpe": "cpe:/a:redhat:openshift_security_profiles_operator:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/spiffe-spire-agent-1-13-3",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/spiffe-spire-agent-1-12-4",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-32288\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-32288\nhttps://go.dev/cl/763766\nhttps://go.dev/issue/78301\nhttps://groups.google.com/g/golang-announce/c/0uYbvbPZRWU\nhttps://pkg.go.dev/vuln/GO-2026-4869"
    ],
    "name": "CVE-2026-32288",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-13T17:49:34Z",
    "bugzilla": {
      "description": "jq: jq: Denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow",
      "id": "2457929",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457929"
    },
    "cvss3": {
      "cvss3_base_score": "6.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31 bytes causes a 32-bit unsigned integer overflow in the buffer allocation size calculation, resulting in a drastically undersized heap buffer. Subsequent memory copy operations then write the full string data into this undersized buffer, causing a heap buffer overflow classified as CWE-190 (Integer Overflow) leading to CWE-122 (Heap-based Buffer Overflow). Any system evaluating untrusted jq queries is affected, as an attacker can crash the process or potentially achieve further exploitation through heap corruption by crafting queries that produce extremely large strings. The root cause is the absence of string size bounds checking, unlike arrays and objects which already have size limits. The issue has been addressed in commit e47e56d226519635768e6aab2f38f0ab037c09e5.",
      "A flaw was found in jq, a command-line JSON processor. An attacker can exploit an integer overflow vulnerability by crafting queries that produce extremely large strings. This causes a 32-bit unsigned integer overflow in the buffer allocation size calculation, leading to a drastically undersized memory buffer. Subsequent memory copy operations then write the full string data into this undersized buffer, causing a heap-based buffer overflow. This can result in a Denial of Service (DoS) by crashing the process or potentially allow for further exploitation through heap corruption."
    ],
    "statement": "This Moderate impact vulnerability in `jq`, a command-line JSON processor, allows for a Denial of Service or potential arbitrary code execution. The flaw occurs when `jq` processes untrusted queries that generate excessively large strings, leading to an integer overflow and heap-based buffer overflow. Red Hat products that utilize `jq` for processing JSON data are affected if they handle untrusted `jq` queries.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8579",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.1-3.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-32316\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-32316\nhttps://github.com/jqlang/jq/commit/e47e56d226519635768e6aab2f38f0ab037c09e5\nhttps://github.com/jqlang/jq/security/advisories/GHSA-q3h9-m34w-h76f"
    ],
    "name": "CVE-2026-32316",
    "mitigation": {
      "value": "To mitigate this issue, avoid processing untrusted or unvalidated JSON input with the `jq` utility. Ensure that any scripts or automated processes utilizing `jq` only operate on trusted data sources. Restricting the execution of `jq` to trusted users and environments can also reduce exposure.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-06T14:32:43Z",
    "bugzilla": {
      "description": "apr-util: Apache Portable Runtime Utility: Denial of Service via XML stack recursion attack",
      "id": "2512079",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2512079"
    },
    "cvss3": {
      "cvss3_base_score": "6.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-776",
    "details": [
      "A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.\nUsers are recommended to upgrade to version 1.6.4, which fixes this issue.",
      "A flaw was found in Apache Portable Runtime Utility (apr-util). A remote attacker could exploit a stack recursion vulnerability by providing specially crafted XML input to a library consumer that uses the `apr_xml_quote_elem()` function. This could lead to a denial of service (DoS) due to an application crash."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-22T00:00:00Z",
        "advisory": "RHSA-2026:58474",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "apr-util-main-1.6.5-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-32327\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-32327\nhttps://lists.apache.org/thread/hq27vj8yfno9tkwv0fpj6jksfzgxvth1"
    ],
    "name": "CVE-2026-32327",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-12T21:41:50Z",
    "bugzilla": {
      "description": "pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)",
      "id": "2447194",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447194"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-347",
    "details": [
      "PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.",
      "A missing verification step has been discovered in PyJWT. PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13512",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "automation-controller-0:4.6.28-3.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13512",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "python3.12-pyjwt-0:2.12.1-1.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13512",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "automation-controller-0:4.6.28-3.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13512",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "python3.12-pyjwt-0:2.12.1-1.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13508",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "automation-controller-0:4.7.11-2.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13508",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "python3.12-pyjwt-0:2.12.1-1.el9ap"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13916",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "fence-agents-0:4.16.0-13.el10_1.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19138",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "fence-agents-0:4.16.0-21.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17083",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "fence-agents-0:4.16.0-5.el10_0.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12176",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "fence-agents-0:4.2.1-129.el8_10.25"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13672",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "fence-agents-0:4.10.0-98.el9_7.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19355",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "fence-agents-0:4.10.0-110.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22330",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "fence-agents-0:4.10.0-43.el9_2.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21517",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "fence-agents-0:4.10.0-62.el9_4.24"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21431",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "fence-agents-0:4.10.0-86.el9_6.16"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8746",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1775680192"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8747",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1775680262"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8748",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1775749857"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13553",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "ansible-automation-platform-25/gateway-rhel8:1777394109"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13553",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "ansible-automation-platform-25/lightspeed-rhel8:1777403872"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/eda-controller-rhel9:1777296732"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/ee-supported-rhel9:1777391447"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/gateway-rhel9:1777311120"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/hub-rhel9:1777299023"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-chatbot-rhel9:1777398576"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-rhel9:1777387242"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13545",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/mcp-tools-rhel9:1777311601"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10140",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-aws-cuda-rhel9:1776871984"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10140",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-azure-cuda-rhel9:1776871985"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10140",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-azure-rocm-rhel9:1776872005"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10140",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-cuda-rhel9:1776773390"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10140",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-gcp-cuda-rhel9:1776871987"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10140",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/bootc-rocm-rhel9:1776773505"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10141",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "rhelai3/disk-image-cuda-rhel9:1776938871"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-feature-server-rhel9:1776338381"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10184",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-kserve-storage-initializer-rhel9:1776343111"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-vllm-gaudi-rhel9:1780069069"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1783696512"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1783616068"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1783998551"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:1783664916"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1783615385"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1783664921"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1783696507"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1783615414"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1783998585"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1783664921"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1783615165"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1783664921"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1783615432"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-vllm-cpu-rhel9:1778264363"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-vllm-gaudi-rhel9:1778600187"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9:1782472374"
      },
      {
        "product_name": "Red Hat Quay 3.1",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6912",
        "cpe": "cpe:/a:redhat:quay:3.10::el8",
        "package": "quay/quay-rhel8:1775169155"
      },
      {
        "product_name": "Red Hat Quay 3.12",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6720",
        "cpe": "cpe:/a:redhat:quay:3.12::el8",
        "package": "quay/quay-rhel8:1775253092"
      },
      {
        "product_name": "Red Hat Quay 3.15",
        "release_date": "2026-04-03T00:00:00Z",
        "advisory": "RHSA-2026:6568",
        "cpe": "cpe:/a:redhat:quay:3.15::el8",
        "package": "quay/quay-rhel8:1775169219"
      },
      {
        "product_name": "Red Hat Quay 3.16",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19375",
        "cpe": "cpe:/a:redhat:quay:3.16::el9",
        "package": "quay/quay-rhel9:1779204086"
      },
      {
        "product_name": "Red Hat Quay 3.9",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6926",
        "cpe": "cpe:/a:redhat:quay:3.9::el8",
        "package": "quay/quay-rhel8:1775169218"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26226",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/iop-host-inventory-rhel9:1780414237"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.4",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8437",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.4::el9",
        "package": "rhtas/model-transparency-rhel9:1775815407"
      }
    ],
    "package_state": [
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Will not fix",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-tech-preview/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "satellite/foreman-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/segment-reporting-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-32597\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-32597\nhttps://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f"
    ],
    "name": "CVE-2026-32597",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-18T20:39:44Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via out-of-bounds write in NewXMLTree method",
      "id": "2448862",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448862"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.",
      "A flaw was found in ImageMagick. The NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. This vulnerability could allow a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted image, leading to system instability or unavailability."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17618",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "ImageMagick-0:6.9.10.68-16.el7_9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-32636\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-32636\nhttps://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-17\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gc62-2v5p-qpmp\nhttps://github.com/dlemstra/Magick.NET/releases/tag/14.11.0"
    ],
    "name": "CVE-2026-32636",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-24T18:00:00Z",
    "bugzilla": {
      "description": "nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files",
      "id": "2449598",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449598"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. \nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in NGINX's ngx_http_mp4_module. This Out-of-Bounds Read/Write vulnerability occurs due to improper handling of specially crafted MP4 files. A local authenticated attacker, by supplying a malicious MP4 file, can trigger a buffer over-read or overwrite in worker memory. This can lead to process termination, potentially causing a denial-of-service or, under certain conditions, achieving code execution."
    ],
    "statement": "This IMPORTANT vulnerability in the NGINX ngx_http_mp4_module is due to improper handling of specially crafted MP4 files. A local authenticated attacker could exploit this flaw by providing a malicious MP4 file, leading to a denial of service or potentially arbitrary code execution. Red Hat products utilizing NGINX with the ngx_http_mp4_module enabled are affected if untrusted MP4 files are processed.",
    "acknowledgement": "Red Hat would like to thank Pavel Kohout (Aisle Research) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6906",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nginx-2:1.26.3-2.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13634",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "nginx-2:1.26.3-1.el10_0.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6907",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nginx:1.24-8100020260401080144.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6923",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.24-9070020260331134728.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7002",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx-2:1.20.1-24.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7343",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.26-9070020260407080353.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15942",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "nginx-1:1.20.1-10.el9_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14836",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "nginx-1:1.20.1-14.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13839",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nginx-1:1.20.1-16.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15943",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nginx:1.24-9040020260504195322.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13680",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx-2:1.20.1-22.el9_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15945",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx:1.24-9060020260504194843.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15966",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx:1.26-9060020260504154614.9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8346",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nginx-main-1.30.0-1.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1776868774"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Lightspeed proxy 1",
        "fix_state": "Affected",
        "package_name": "insights-proxy/insights-proxy-container-rhel9",
        "cpe": "cpe:/a:redhat:insights_proxy:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-32647\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-32647\nhttps://my.f5.com/manage/s/article/K000160366"
    ],
    "name": "CVE-2026-32647",
    "mitigation": {
      "value": "To mitigate this issue, disable the ngx_http_mp4_module in your NGINX configuration if MP4 file processing is not required. This can be done by commenting out or removing the mp4 directive from the NGINX configuration file. After modifying the configuration, a reload or restart of the NGINX service is required for the changes to take effect.\nAlternatively, restrict access to the NGINX server to trusted networks and users to prevent the upload and processing of malicious MP4 files.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-03T14:29:39Z",
    "bugzilla": {
      "description": "python: Python unicodedata: Denial of Service due to excessive CPU consumption",
      "id": "2484424",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484424"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-606",
    "details": [
      "unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.",
      "A flaw was found in the `unicodedata.normalize()` function in Python. This vulnerability allows a remote attacker to cause excessive CPU consumption by providing specially crafted Unicode input. Successful exploitation can lead to a Denial of Service (DoS) on the affected system."
    ],
    "statement": "Moderate: A flaw in the `unicodedata.normalize()` function in Python can lead to excessive CPU consumption when processing specially crafted Unicode input. This vulnerability could result in a Denial of Service on systems where applications process untrusted Unicode data using this function, impacting the availability of affected Red Hat products.",
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Fix deferred",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python3.12",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python3.14",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3.12",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.12",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.14",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.9",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-cuda-12.9-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-cuda-13.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-neuron-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-rocm-6.4-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-rocm-7.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-rocm-7.1-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-spyre-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-tpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-automl-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-autorag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-built-in-detector-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-nlp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-tgis-serving-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-guardrails-detector-huggingface-runtime-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-autogluon-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llm-d-inference-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llm-d-kv-cache-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llm-d-routing-sidecar-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlserver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-modelmesh-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipelines-components-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-rhaii-cluster-validator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-rhaii-validator-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-spark-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-service-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/rhai-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-3276\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-3276\nhttps://github.com/python/cpython/issues/149079\nhttps://github.com/python/cpython/pull/149080\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/"
    ],
    "name": "CVE-2026-3276",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-16T06:54:20Z",
    "bugzilla": {
      "description": "libexpat: libexpat: Denial of Service due to NULL pointer dereference",
      "id": "2447888",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447888"
    },
    "cvss3": {
      "cvss3_base_score": "6.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-476",
    "details": [
      "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
      "A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted XML content with empty external parameter entities. This could lead to a NULL pointer dereference, causing the application to crash and resulting in a Denial of Service (DoS)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "compat-expat1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-32776\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-32776\nhttps://github.com/libexpat/libexpat/pull/1158\nhttps://github.com/libexpat/libexpat/pull/1159"
    ],
    "name": "CVE-2026-32776",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-16T06:58:06Z",
    "bugzilla": {
      "description": "libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing",
      "id": "2447890",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447890"
    },
    "cvss3": {
      "cvss3_base_score": "4.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "details": [
      "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
      "A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted Document Type Definition (DTD) content. This could lead to an infinite loop during parsing, resulting in a Denial of Service (DoS) for the application using libexpat."
    ],
    "statement": "This MODERATE impact flaw in libexpat can lead to a denial of service when processing specially crafted Document Type Definition (DTD) content, causing an infinite loop during parsing.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "compat-expat1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-32777\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-32777\nhttps://github.com/libexpat/libexpat/issues/1161\nhttps://github.com/libexpat/libexpat/pull/1159\nhttps://github.com/libexpat/libexpat/pull/1162\nhttps://issues.oss-fuzz.com/issues/486993411"
    ],
    "name": "CVE-2026-32777",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-16T07:02:34Z",
    "bugzilla": {
      "description": "libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition",
      "id": "2447885",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447885"
    },
    "cvss3": {
      "cvss3_base_score": "5.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-476",
    "details": [
      "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
      "A flaw was found in libexpat. This vulnerability allows an attacker to trigger a NULL pointer dereference in the `setContext` function. This occurs when the system attempts to retry an operation after an out-of-memory condition, which can lead to a Denial of Service (DoS) for the affected application."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "compat-expat1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-32778\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-32778\nhttps://github.com/libexpat/libexpat/pull/1159\nhttps://github.com/libexpat/libexpat/pull/1163"
    ],
    "name": "CVE-2026-32778",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-04T14:42:03Z",
    "bugzilla": {
      "description": "httpd: mod_auth_digest: timing attack allows a bypass of digest authentication",
      "id": "2465293",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2465293"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-208",
    "details": [
      "A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker.\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.",
      "A flaw was found in the mod_auth_digest module of httpd. A remote unauthenticated attacker can bypass digest authentication by measuring timing discrepancies of requests. This issue leads to unauthorized access to resources protected by digest authentication."
    ],
    "statement": "To exploit this vulnerability, an attacker needs to send a high volume of specific requests to the server. These payloads are used to trigger the vulnerable and non-constant-time code path to perform statistical analysis on the resulting timing variations, increasing the complexity of exploitation. The primary security impact of this issue is the unauthorized access to resources protected by digest authentication. Due to these reasons, this flaw has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34109",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41906",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.5"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17080",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.67-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "httpd:2.4/httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "mod_auth_digest.so",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33006\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33006\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-33006",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-04T14:41:27Z",
    "bugzilla": {
      "description": "httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash",
      "id": "2465299",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2465299"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration.\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.",
      "A flaw was found in the mod_authn_socache module of httpd. This vulnerability allows an unauthenticated remote user to crash a child process due to a NULL pointer dereference when the server is operating in a caching forward proxy configuration."
    ],
    "statement": "This issue allows an unauthenticated remote attacker to cause a crash in a child process. However, the main parent process remains active and functional. Due to this reason, this flaw has been rated with a moderate severity.\nThis flaw only affects configurations with mod_authn_socache loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.",
    "affected_release": [
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el7jbcs"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21433",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47046",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "httpd-0:2.4.63-1.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22140",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "httpd:2.4-8100020260519200905.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36846",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "httpd:2.4-8040020260702193120.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36846",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "httpd:2.4-8040020260702193120.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36831",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "httpd:2.4-8060020260702195216.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36831",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "httpd:2.4-8060020260702195216.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36373",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "httpd:2.4-8080020260702200145.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36373",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "httpd:2.4-8080020260702200145.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21391",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.1"
      },
      {
        "product_name": "Red Hat JBoss Core Services 2.4.62.SP4",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27201",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "mod_authn_socache.so"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13938",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.67-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33007\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33007\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-33007",
    "mitigation": {
      "value": "Disabling mod_authn_socache and restarting httpd will mitigate this flaw.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-07T14:22:48Z",
    "bugzilla": {
      "description": "Django: Django: Performance degradation via excessive whitespace in multipart uploads",
      "id": "2455962",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455962"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-1286",
    "details": [
      "An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.\n`MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Seokchan Yoon for reporting this issue.",
      "A flaw was found in Django. A remote attacker can exploit this vulnerability by submitting specially crafted multipart uploads that include excessive whitespace within `Content-Transfer-Encoding: base64` data. This can lead to a degradation of performance, effectively causing a Denial of Service (DoS) for the affected system."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/automation-reports",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Under investigation",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/discovery-server",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/iop-advisor-backend-sat-6-18",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Under investigation",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Self-service automation portal 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform/bootc-automation-portal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_portal:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33033\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33033\nhttps://docs.djangoproject.com/en/dev/releases/security/\nhttps://groups.google.com/g/django-announce\nhttps://www.djangoproject.com/weblog/2026/apr/07/security-releases/"
    ],
    "name": "CVE-2026-33033",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-14T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were verified as part of a signed configuration. mkimage(1) sets the hashed-nodes property of the FIT signature node to list which nodes of the FIT were hashed as part of the signing process as these will need to be verified later on by the bootloader. However, hashed-nodes itself is not part of the hash and could therefore be modified to allow booting different images than those that have been verified. This issue has been patched in barebox versions 2026.03.1 and backported to 2025.09.3."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33243\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33243"
    ],
    "name": "CVE-2026-33243",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the slice descriptor bounds, allowing a cstring longer than the allocated buffer to overflow it. An unauthenticated attacker can exploit this by sending a crafted packet to the server, potentially causing a crash or other security impact. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33337\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33337"
    ],
    "name": "CVE-2026-33337",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-24T19:43:07Z",
    "bugzilla": {
      "description": "vim: Vim: Arbitrary code execution via command injection in glob() function",
      "id": "2450907",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450907"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-78",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This vulnerability depends on the user's 'shell' setting. This issue has been patched in version 9.2.0202.",
      "A flaw was found in Vim. By including a newline character in a pattern passed to Vim's glob() function, an attacker may be able to execute arbitrary shell commands. This command injection vulnerability allows for arbitrary code execution, depending on the user's shell settings."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7711",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "vim-2:9.1.083-6.el10_1.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6502",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6725",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "vim-2:7.4.629-5.el6_10.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6617",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "vim-2:7.4.629-8.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6915",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-22.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6915",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-22.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6730",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "vim-2:8.0.1763-13.el8_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6729",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6729",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6731",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6731",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6731",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6736",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6736",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8259",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-23.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8259",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-23.el9_7.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6619",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "vim-2:8.2.2637-16.el9_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6620",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "vim-2:8.2.2637-20.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6540",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "vim-2:8.2.2637-20.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6539",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "vim-2:8.2.2637-22.el9_6.2"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-08T00:00:00Z",
        "advisory": "RHSA-2026:12274",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202604281506-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7239",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202604080111-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:15087",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202605060243-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14773",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202605060220-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10097",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202604211449-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17596",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202605112123-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8423",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202604140044-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7243",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202604080618-0"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7335",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1775740563"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16008",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1778244559"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16009",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1778244531"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9832",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1776868961"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1776868774"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1776868744"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1776868772"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1777459441"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1777454300"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1777459504"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33412\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33412\nhttps://github.com/vim/vim/commit/645ed6597d1ea896c712cd7ddbb6edee79577e9a\nhttps://github.com/vim/vim/releases/tag/v9.2.0202\nhttps://github.com/vim/vim/security/advisories/GHSA-w5jw-f54h-x46c"
    ],
    "name": "CVE-2026-33412",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-26T16:48:54Z",
    "bugzilla": {
      "description": "libpng: libpng: Arbitrary code execution due to use-after-free vulnerability",
      "id": "2451805",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451805"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through 1.6.55, `png_set_tRNS` and `png_set_PLTE` each alias a heap-allocated buffer between `png_struct` and `png_info`, sharing a single allocation across two structs with independent lifetimes. The `trans_alpha` aliasing has been present since at least libpng 1.0, and the `palette` aliasing since at least 1.2.1. Both affect all prior release lines `png_set_tRNS` sets `png_ptr->trans_alpha = info_ptr->trans_alpha` (256-byte buffer) and `png_set_PLTE` sets `info_ptr->palette = png_ptr->palette` (768-byte buffer). In both cases, calling `png_free_data` (with `PNG_FREE_TRNS` or `PNG_FREE_PLTE`) frees the buffer through `info_ptr` while the corresponding `png_ptr` pointer remains dangling. Subsequent row-transform functions dereference and, in some code paths, write to the freed memory. A second call to `png_set_tRNS` or `png_set_PLTE` has the same effect, because both functions call `png_free_data` internally before reallocating the `info_ptr` buffer. Version 1.6.56 fixes the issue.",
      "A flaw was found in libpng, a library used for processing PNG (Portable Network Graphics) image files. This vulnerability arises from improper memory management where a heap-allocated buffer is aliased between internal data structures. When specific functions are called, a freed memory region can still be referenced, leading to a use-after-free condition. An attacker could potentially exploit this to achieve arbitrary code execution or cause a denial of service."
    ],
    "affected_release": [
      {
        "product_name": "OPENJDK ELS 11.0.31",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9255",
        "cpe": "cpe:/a:redhat:openjdk_els:11",
        "package": "java-11-openjdk-portable"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18064",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "libpng-2:1.6.40-8.el10_1.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7672",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "firefox-0:140.9.1-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9638",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "thunderbird-0:140.9.1-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9689",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "java-21-openjdk-1:21.0.11.0.10-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "java-25-openjdk-1:25.0.3.0.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28233",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libpng-2:1.6.40-11.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11813",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "thunderbird-0:140.9.1-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13665",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "firefox-0:140.9.1-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20551",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libpng-2:1.6.40-8.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9689",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "java-21-openjdk-1:21.0.11.0.10-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13977",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "firefox-0:140.9.1-2.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43702",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libpng12-0:1.2.50-10.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50808",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libpng-2:1.5.13-8.el7_9.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26347",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libpng15-0:1.5.30-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26348",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libpng12-0:1.2.57-7.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8052",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "firefox-0:140.9.1-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9345",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "thunderbird-0:140.9.1-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9689",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-21-openjdk-1:21.0.11.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29898",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "libpng-2:1.6.34-11.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11805",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "firefox-0:140.9.1-1.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13600",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "firefox-0:140.9.1-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14303",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "thunderbird-0:140.9.1-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29021",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libpng15-0:1.5.30-7.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29022",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libpng12-0:1.2.57-5.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29902",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "libpng-2:1.6.34-8.el8_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13600",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "firefox-0:140.9.1-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14303",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "thunderbird-0:140.9.1-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29021",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libpng15-0:1.5.30-7.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29022",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libpng12-0:1.2.57-5.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29902",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "libpng-2:1.6.34-8.el8_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13683",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "firefox-0:140.9.1-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15889",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "thunderbird-0:140.9.1-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29019",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libpng15-0:1.5.30-7.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29020",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libpng12-0:1.2.57-5.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29901",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "libpng-2:1.6.34-8.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29019",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libpng15-0:1.5.30-7.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29020",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libpng12-0:1.2.57-5.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29901",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "libpng-2:1.6.34-8.el8_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13683",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "firefox-0:140.9.1-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15889",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "thunderbird-0:140.9.1-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13683",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "firefox-0:140.9.1-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15889",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "thunderbird-0:140.9.1-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13682",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "firefox-0:140.9.1-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14223",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "thunderbird-0:140.9.1-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29016",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libpng15-0:1.5.30-7.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29018",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libpng12-0:1.2.57-5.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29900",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "libpng-2:1.6.34-8.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13682",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "firefox-0:140.9.1-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14223",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "thunderbird-0:140.9.1-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29016",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libpng15-0:1.5.30-7.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29018",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libpng12-0:1.2.57-5.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29900",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "libpng-2:1.6.34-8.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18028",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libpng-2:1.6.37-12.el9_7.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28244",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libpng15-0:1.5.30-15.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28255",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libpng-2:1.6.37-15.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7671",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "firefox-0:140.9.1-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8459",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "thunderbird-0:140.9.1-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-17-openjdk-1:17.0.19.0.10-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9689",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-21-openjdk-1:21.0.11.0.10-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9693",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-25-openjdk-1:25.0.3.0.9-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18028",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libpng-2:1.6.37-12.el9_7.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28255",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libpng-2:1.6.37-15.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12264",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "thunderbird-0:140.9.1-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13596",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "firefox-0:140.9.1-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13412",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "thunderbird-0:140.9.1-1.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13922",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "firefox-0:140.9.1-1.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20550",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libpng-2:1.6.37-12.el9_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28458",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libpng15-0:1.5.30-14.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13533",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "thunderbird-0:140.9.1-1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13582",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "firefox-0:140.9.1-1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20549",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "libpng-2:1.6.37-12.el9_4.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9689",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-21-openjdk-1:21.0.11.0.10-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28457",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "libpng15-0:1.5.30-14.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13342",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "thunderbird-0:140.9.1-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13583",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "firefox-0:140.9.1-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20548",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libpng-2:1.6.37-12.el9_6.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:28456",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libpng15-0:1.5.30-14.el9_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9689",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "java-21-openjdk-1:21.0.11.0.10-1.el9"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 7",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9254",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el7",
        "package": "java-11-openjdk-1:11.0.31.0.11-1.el7_9"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 8",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9254",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el8",
        "package": "java-11-openjdk-1:11.0.31.0.11-1.el8"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 9",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9254",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el9",
        "package": "java-11-openjdk-1:11.0.31.0.11-1.el9"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33313",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782756541"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6732",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libpng-main-1.6.56-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Affected",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Not affected",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Not affected",
        "package_name": "java-21-openjdk-vanilla",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Not affected",
        "package_name": "java-25-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Affected",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Affected",
        "package_name": "java-17-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Not affected",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Not affected",
        "package_name": "java-21-openjdk-vanilla",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Not affected",
        "package_name": "java-25-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 1.8",
        "fix_state": "Affected",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:1.8"
      },
      {
        "product_name": "Red Hat build of OpenJDK 1.8",
        "fix_state": "Affected",
        "package_name": "java-1.8.0-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:1.8"
      },
      {
        "product_name": "Red Hat build of OpenJDK 1.8",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:1.8"
      },
      {
        "product_name": "Red Hat build of OpenJDK 1.8",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk-vanilla",
        "cpe": "cpe:/a:redhat:openjdk:1.8"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Not affected",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk-vanilla",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Not affected",
        "package_name": "java-25-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 25",
        "fix_state": "Affected",
        "package_name": "java-25-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:25"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "libpng",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "mingw-libpng",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33416\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33416\nhttps://github.com/pnggroup/libpng/commit/23019269764e35ed8458e517f1897bd3c54820eb\nhttps://github.com/pnggroup/libpng/commit/7ea9eea884a2328cc7fdcb3c0c00246a50d90667\nhttps://github.com/pnggroup/libpng/commit/a3a21443ed12bfa1ef46fa0d4fb2b74a0fa34a25\nhttps://github.com/pnggroup/libpng/commit/c1b0318b393c90679e6fa5bc1d329fd5d5012ec1\nhttps://github.com/pnggroup/libpng/pull/824\nhttps://github.com/pnggroup/libpng/security/advisories/GHSA-m4pc-p4q3-4c7j"
    ],
    "name": "CVE-2026-33416",
    "mitigation": {
      "value": "To reduce exposure, avoid processing untrusted PNG image files with applications that utilize libpng. Restricting the source of PNG images to trusted origins can limit the attack surface.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-26T00:13:51Z",
    "bugzilla": {
      "description": "Squid: Squid: Information disclosure via improper input validation in ICP traffic",
      "id": "2451581",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451581"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling ICP traffic. This problem allows a remote attacker to receive small amounts of memory potentially containing sensitive information when responding with errors to invalid ICP requests. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem cannot be mitigated by denying ICP queries using `icp_access` rules. Version 7.5 contains a patch.",
      "A flaw was found in Squid, a caching proxy for the Web. Due to improper input validation, Squid is vulnerable to an out-of-bounds read when handling Internet Cache Protocol (ICP) traffic. A remote attacker can exploit this by sending invalid ICP requests, potentially receiving small amounts of memory containing sensitive information. This vulnerability is limited to Squid deployments that have explicitly enabled ICP support."
    ],
    "statement": "This flaw in Squid has Moderate impact. It is only exploitable in Red Hat products if Squid is configured to explicitly enable ICP support (i.e., `icp_port` is set to a non-zero value), which is not the default configuration. This issue cannot be mitigated by `icp_access` rules.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "squid34",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "squid:4/squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33515\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33515\nhttp://www.openwall.com/lists/oss-security/2026/03/25/4\nhttps://github.com/squid-cache/squid/commit/8138e909d2058d4401e0ad49b583afaec912b165\nhttps://github.com/squid-cache/squid/pull/2220\nhttps://github.com/squid-cache/squid/pull/2220#discussion_r2727683637\nhttps://github.com/squid-cache/squid/security/advisories/GHSA-84p4-hcx7-jj7c"
    ],
    "name": "CVE-2026-33515",
    "mitigation": {
      "value": "To mitigate this vulnerability, ensure that Internet Cache Protocol (ICP) support is disabled in Squid. This can be achieved by setting `icp_port` to `0` or commenting out the `icp_port` directive in the `squid.conf` configuration file. After modifying the configuration, the Squid service must be restarted for the changes to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-04T14:40:41Z",
    "bugzilla": {
      "description": "httpd: HTTP response splitting forwarding malicious status line",
      "id": "2465297",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2465297"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-93",
    "details": [
      "HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.\nThis issue affects Apache HTTP Server: from through 2.4.66.\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.",
      "A flaw was found in httpd. When processing responses from an untrusted or compromised backend server, multiple modules fail to sanitize Carriage Return and Line Feed (CRLF) sequences in the HTTP status line. This issue leads to an HTTP response splitting attack."
    ],
    "statement": "To exploit this vulnerability, the Apache HTTP Server must be configured to connect to an untrusted or compromised backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17080",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.67-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "httpd:2.4/httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Affected",
        "package_name": "jbcs-httpd24-httpd",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33523\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33523\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-33523",
    "mitigation": {
      "value": "To mitigate this issue, ensure that Apache HTTP Server (httpd) is configured to proxy only to trusted backend services. Implement robust network segmentation and access controls to restrict unauthorized access to backend servers. If proxying to potentially untrusted backends is necessary, consider deploying a Web Application Firewall (WAF) or an additional content inspection layer to filter malicious response headers.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-26T00:16:12Z",
    "bugzilla": {
      "description": "squid: Squid: Denial of Service via heap Use-After-Free vulnerability in ICP handling",
      "id": "2451574",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451574"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. Version 7.5 contains a patch.",
      "A flaw was found in Squid. A remote attacker can exploit a heap Use-After-Free vulnerability when handling ICP (Internet Cache Protocol) traffic. This allows them to perform a reliable and repeatable Denial of Service (DoS) attack, making the Squid service unavailable. This attack is limited to deployments where ICP support is explicitly enabled."
    ],
    "statement": "Important: A heap Use-After-Free vulnerability in Squid's ICP handling can lead to a denial of service. This flaw affects Red Hat products where the Squid proxy is configured to explicitly enable Internet Cache Protocol (ICP) support by setting a non-zero `icp_port`. Deployments with default configurations, where ICP is typically disabled, are not affected.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8119",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "squid-7:6.10-6.el10_1.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11901",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "squid-7:6.10-5.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8880",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "squid-7:3.5.20-17.el7_9.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-15T00:00:00Z",
        "advisory": "RHSA-2026:8317",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "squid:4-8100020260408092701.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20564",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "squid:4-8040020260514123440.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20564",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "squid:4-8040020260514123440.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20565",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "squid:4-8060020260518090356.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20565",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "squid:4-8060020260518090356.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20565",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "squid:4-8060020260518090356.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20580",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "squid:4-8080020260514105733.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20580",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "squid:4-8080020260514105733.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-31T00:00:00Z",
        "advisory": "RHSA-2026:6301",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "squid-7:5.5-22.el9_7.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10256",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "squid-7:5.2-1.el9_0.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10257",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "squid-7:5.5-5.el9_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:10255",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "squid-7:5.5-13.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9220",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "squid-7:5.5-19.el9_6.3"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "squid34",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33526\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33526\nhttp://www.openwall.com/lists/oss-security/2026/03/25/2\nhttps://github.com/squid-cache/squid/commit/8a7d42f9d44befb8fcbbb619505587c8de6a1e91\nhttps://github.com/squid-cache/squid/security/advisories/GHSA-hpfx-h48q-gvwg"
    ],
    "name": "CVE-2026-33526",
    "mitigation": {
      "value": "To mitigate this issue, disable ICP support in Squid by ensuring that `icp_port` is set to `0` in the `squid.conf` configuration file. This will prevent Squid from processing ICP traffic and eliminate the attack vector. After modifying the configuration, the Squid service must be restarted for the changes to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-03-26T19:52:30Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via out-of-bounds write in X11 display interaction path",
      "id": "2451855",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451855"
    },
    "cvss3": {
      "cvss3_base_score": "4.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the issue.",
      "A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. A local attacker could exploit an out-of-bounds write of a zero byte in the X11 display interaction path. This vulnerability, a type of memory corruption, could lead to a crash of the application, resulting in a Denial of Service (DoS)."
    ],
    "statement": "Low impact. This flaw in ImageMagick's X11 display interaction path requires local access to trigger an out-of-bounds write, leading to a denial of service. Red Hat Enterprise Linux systems are affected if ImageMagick is installed and used in an X11 environment.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33535\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33535\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mw3m-pqr2-qv7c"
    ],
    "name": "CVE-2026-33535",
    "mitigation": {
      "value": "For systems where ImageMagick is not required, especially in server environments without a graphical interface, consider removing the `ImageMagick` package to eliminate the attack surface. This action may impact applications that rely on ImageMagick for image processing.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-26T19:57:53Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via out-of-bounds write",
      "id": "2451849",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451849"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-823",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, due to an incorrect return value on certain platforms a pointer is incremented past the end of a buffer that is on the stack and that could result in an out of bounds write. Versions 7.1.2-18 and 6.9.13-43 patch the issue.",
      "A flaw was found in ImageMagick, an open-source software for image manipulation. This vulnerability, caused by an incorrect return value, allows a local attacker to write data outside of its intended memory area, known as an out-of-bounds write. The primary consequence of this flaw is a denial of service (DoS), which can make the application or system unavailable."
    ],
    "statement": "Moderate: This flaw in ImageMagick, an image manipulation software, allows a local attacker to cause a denial of service due to an out-of-bounds write. This vulnerability affects Red Hat Enterprise Linux 6 ELS and 7 ELS, as well as community projects like Fedora and EPEL, where ImageMagick is installed and used for image processing.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33536\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33536\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8793-7xv6-82cf"
    ],
    "name": "CVE-2026-33536",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-24T00:00:00Z",
    "bugzilla": {
      "description": "freeipmi: buffer overflows on response messages via ipmi-oem",
      "id": "2450778",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450778"
    },
    "cvss3": {
      "cvss3_base_score": "8.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: \"ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers,\" \"ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermicro servers,\" and \"ipmi-oem wistron read-proprietary-string - read a proprietary string on Wistron servers.\"",
      "A flaw was found in FreeIPMI. The `ipmi-oem` program is used to send Intelligent Platform Management Interface (IPMI) OEM commands for specific hardware vendors to retrieve specific information from the hardware. A malicious server can reply with crafted response messages and cause buffer overflows when processed, potentially resulting in a denial of service and memory corruption."
    ],
    "statement": "To exploit this vulnerability, a user needs to execute the `ipmi-oem` program to retrieve information from a compromised or malicious Baseboard Management Controller (BMC) server, limiting the exposure of this flaw.\nSpecifically, the following `ipmi-oem` commands are vulnerable to this issue:\n- ipmi-oem dell get-last-post-code\n- ipmi-oem supermicro extra-firmware-info\n- ipmi-oem wistron read-proprietary-string\nDefault Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability.\nDue to these reasons, this flaw has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13515",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "freeipmi-0:1.6.17-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19053",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freeipmi-0:1.6.17-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:39007",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freeipmi-0:1.6.14-4.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48826",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "freeipmi-0:1.5.7-3.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20579",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "freeipmi-0:1.6.17-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50729",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "freeipmi-0:1.6.6-1.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50729",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "freeipmi-0:1.6.6-1.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50772",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "freeipmi-0:1.6.8-1.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50772",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "freeipmi-0:1.6.8-1.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50769",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "freeipmi-0:1.6.8-1.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50769",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "freeipmi-0:1.6.8-1.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14819",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freeipmi-0:1.6.17-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19208",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freeipmi-0:1.6.17-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:39010",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freeipmi-0:1.6.14-2.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:39008",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "freeipmi-0:1.6.14-2.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:39006",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freeipmi-0:1.6.14-2.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "freeipmi",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33554\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33554\nhttps://ftp.gnu.org/gnu/freeipmi/\nhttps://savannah.gnu.org/bugs/?68140\nhttps://savannah.gnu.org/bugs/?68141\nhttps://savannah.gnu.org/bugs/?68142"
    ],
    "name": "CVE-2026-33554",
    "mitigation": {
      "value": "To mitigate this issue, ensure all BMCs and the servers running FreeIPMI are isolated on a dedicated and restricted network environment.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-12T13:28:44Z",
    "bugzilla": {
      "description": "dovecot: Dovecot: Information disclosure via SCRAM TLS channel binding bypass",
      "id": "2476464",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476464"
    },
    "cvss3": {
      "cvss3_base_score": "6.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "status": "draft"
    },
    "cwe": "CWE-940",
    "details": [
      "Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.",
      "A flaw was found in Dovecot. An attacker, positioned as a Man-in-the-Middle (MITM) between Dovecot and a client, can exploit a specially crafted base64 exchange to fake SCRAM TLS channel binding. This allows the attacker to eavesdrop on communications between Dovecot and the client, leading to information disclosure."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33603\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33603\nhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0002.json"
    ],
    "name": "CVE-2026-33603",
    "mitigation": {
      "value": "To reduce the risk of a Man-in-the-Middle attack, restrict network access to the Dovecot server. Configure firewalls to permit connections only from trusted networks and necessary client IP ranges. This limits an attacker's ability to intercept traffic. If firewall rules are modified, a service reload or restart may be required, which could temporarily disrupt active user sessions.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-26T16:51:58Z",
    "bugzilla": {
      "description": "libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion",
      "id": "2451819",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451819"
    },
    "cvss3": {
      "cvss3_base_score": "7.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-124",
    "details": [
      "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.",
      "A flaw was found in libpng. A remote attacker could exploit an out-of-bounds read and write vulnerability in the ARM/AArch64 Neon-optimized palette expansion path. This occurs when processing a final partial chunk of 8-bit paletted rows without verifying sufficient input pixels, leading to dereferencing pointers before the start of the row buffer and writing expanded pixel data to underflowed positions. This flaw can result in information disclosure and denial of service."
    ],
    "affected_release": [
      {
        "product_name": "OPENJDK ELS 11.0.31",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9255",
        "cpe": "cpe:/a:redhat:openjdk_els:11",
        "package": "java-11-openjdk-portable"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14790",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "libpng-2:1.6.40-8.el10_1.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7672",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "firefox-0:140.9.1-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9638",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "thunderbird-0:140.9.1-1.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9689",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "java-21-openjdk-1:21.0.11.0.10-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "java-25-openjdk-1:25.0.3.0.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28233",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libpng-2:1.6.40-11.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11813",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "thunderbird-0:140.9.1-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13665",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "firefox-0:140.9.1-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17567",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libpng-2:1.6.40-8.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9689",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "java-21-openjdk-1:21.0.11.0.10-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13977",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "firefox-0:140.9.1-2.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-14T00:00:00Z",
        "advisory": "RHSA-2026:8052",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "firefox-0:140.9.1-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9345",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "thunderbird-0:140.9.1-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9689",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "java-21-openjdk-1:21.0.11.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11805",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "firefox-0:140.9.1-1.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13600",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "firefox-0:140.9.1-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14303",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "thunderbird-0:140.9.1-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13600",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "firefox-0:140.9.1-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14303",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "thunderbird-0:140.9.1-1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13683",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "firefox-0:140.9.1-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15889",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "thunderbird-0:140.9.1-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13683",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "firefox-0:140.9.1-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15889",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "thunderbird-0:140.9.1-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13683",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "firefox-0:140.9.1-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15889",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "thunderbird-0:140.9.1-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13682",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "firefox-0:140.9.1-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14223",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "thunderbird-0:140.9.1-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13682",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "firefox-0:140.9.1-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14223",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "thunderbird-0:140.9.1-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14791",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libpng-2:1.6.37-12.el9_7.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28255",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libpng-2:1.6.37-15.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-13T00:00:00Z",
        "advisory": "RHSA-2026:7671",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "firefox-0:140.9.1-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8459",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "thunderbird-0:140.9.1-1.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-17-openjdk-1:17.0.19.0.10-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9689",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-21-openjdk-1:21.0.11.0.10-2.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9693",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "java-25-openjdk-1:25.0.3.0.9-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14791",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libpng-2:1.6.37-12.el9_7.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28255",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libpng-2:1.6.37-15.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12264",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "thunderbird-0:140.9.1-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13596",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "firefox-0:140.9.1-1.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17685",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "libpng-2:1.6.37-12.el9_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13412",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "thunderbird-0:140.9.1-1.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13922",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "firefox-0:140.9.1-1.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17642",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libpng-2:1.6.37-12.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13533",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "thunderbird-0:140.9.1-1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13582",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "firefox-0:140.9.1-1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17603",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "libpng-2:1.6.37-12.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9689",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "java-21-openjdk-1:21.0.11.0.10-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13342",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "thunderbird-0:140.9.1-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13583",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "firefox-0:140.9.1-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17524",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libpng-2:1.6.37-12.el9_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9683",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "java-1.8.0-openjdk-1:1.8.0.492.b09-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9686",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "java-17-openjdk-1:17.0.19.0.10-1.el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:9689",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "java-21-openjdk-1:21.0.11.0.10-1.el9"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 7",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9254",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el7",
        "package": "java-11-openjdk-1:11.0.31.0.11-1.el7_9"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 8",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9254",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el8",
        "package": "java-11-openjdk-1:11.0.31.0.11-1.el8"
      },
      {
        "product_name": "Red Hat OpenJDK 11 els for RHEL 9",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9254",
        "cpe": "cpe:/a:redhat:openjdk_els:11::el9",
        "package": "java-11-openjdk-1:11.0.31.0.11-1.el9"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33313",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782756541"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6732",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libpng-main-1.6.56-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Affected",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk-vanilla",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Affected",
        "package_name": "java-25-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Affected",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Affected",
        "package_name": "java-17-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk-vanilla",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Affected",
        "package_name": "java-25-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 1.8",
        "fix_state": "Affected",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:1.8"
      },
      {
        "product_name": "Red Hat build of OpenJDK 1.8",
        "fix_state": "Affected",
        "package_name": "java-1.8.0-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:1.8"
      },
      {
        "product_name": "Red Hat build of OpenJDK 1.8",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:1.8"
      },
      {
        "product_name": "Red Hat build of OpenJDK 1.8",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk-vanilla",
        "cpe": "cpe:/a:redhat:openjdk:1.8"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Affected",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Affected",
        "package_name": "java-21-openjdk-vanilla",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Affected",
        "package_name": "java-25-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 25",
        "fix_state": "Affected",
        "package_name": "java-25-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:25"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "libpng",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "libpng",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "libpng12",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "libpng",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "libpng12",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "libpng15",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "mingw-libpng",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "libpng15",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33636\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33636\nhttps://github.com/pnggroup/libpng/commit/7734cda20cf1236aef60f3bbd2267c97bbb40869\nhttps://github.com/pnggroup/libpng/commit/aba9f18eba870d14fb52c5ba5d73451349e339c3\nhttps://github.com/pnggroup/libpng/security/advisories/GHSA-wjr5-c57x-95m2"
    ],
    "name": "CVE-2026-33636",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-27T14:04:52Z",
    "bugzilla": {
      "description": "brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern",
      "id": "2452285",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452285"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-606",
    "details": [
      "The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory. Versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13 fix the issue. As a workaround, sanitize strings passed to `expand()` to ensure a step value of `0` is not used.",
      "A flaw was found in the brace-expansion library, a component used for generating strings based on patterns. A remote attacker could exploit this vulnerability by providing a specially crafted brace pattern that includes a zero step value. This malicious input causes the library's sequence generation loop to run indefinitely, leading to excessive memory allocation and causing the process to hang. This results in a Denial of Service (DoS) for the affected application."
    ],
    "statement": "This vulnerability has been rated as Moderate by Red Hat. The vulnerability requires parsing a malformed pattern that, when parsed, leads to infinite looping, excessive memory allocation, and could result in a DoS. The flaw is rated as Moderate because the vulnerable code in the brace-expansion library is not exposed directly as a network service, rather it needs to be called by another application; therefore, some user/system interaction is required to cause the malicious string to be processed.",
    "affected_release": [
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9:1786705347"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9-operator:1786706101"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-core-rhel9:1786705558"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-rhel9-operator:1786705646"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-console-rhel9:1786706138"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-rhel9-operator:1786705741"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1786705777"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-rhel9-operator:1786705802"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cli-rhel9:1786705938"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-console-rhel9:1786706577"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1786706125"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1786706177"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1786706188"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1786706679"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1786706357"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-must-gather-rhel9:1786706612"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-rhel9-operator:1786706644"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odr-rhel9-operator:1786706659"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1786706880"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/cephcsi-rhel9:1787057250"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/cephcsi-rhel9-operator:1787057964"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/devicefinder-rhel9:1787057603"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/mcg-core-rhel9:1787058450"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/mcg-rhel9-operator:1787057989"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-client-console-rhel9:1787059853"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-client-rhel9-operator:1787057849"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1787060257"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-rhel9-operator:1787058278"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-blackbox-exporter-rhel9:1787058658"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cli-rhel9:1787058706"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1787058403"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-console-rhel9:1787059072"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1787058807"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1787058588"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1787058970"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-drbd-rhel9:1787059538"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-external-snapshotter-rhel9-operator:1787059616"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-external-snapshotter-sidecar-rhel9:1787061098"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-lightspeed-rag-content-rhel9:1787059085"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1787059621"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1787059386"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-must-gather-rhel9:1787060080"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-rhel9-operator:1787060105"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-rhel9-operator:1787059493"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-volsync-plugin-mover-rhel9:1787060201"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-volsync-plugin-rhel9-operator:1787060274"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56928",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1787061554"
      }
    ],
    "package_state": [
      {
        "product_name": "Cryostat 4",
        "fix_state": "Fix deferred",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:cryostat:4"
      },
      {
        "product_name": "Gatekeeper 3",
        "fix_state": "Fix deferred",
        "package_name": "gatekeeper/gatekeeper-rhel9",
        "cpe": "cpe:/a:redhat:gatekeeper:3"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Out of support scope",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Fix deferred",
        "package_name": "mta/mta-ui-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Fix deferred",
        "package_name": "rhmtc/openshift-migration-ui-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-console-plugin-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Out of support scope",
        "package_name": "mtv-candidate/mtv-console-plugin-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Fix deferred",
        "package_name": "multicluster-engine/console-mce-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Fix deferred",
        "package_name": "network-observability/network-observability-console-plugin-compat-rhel9",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Fix deferred",
        "package_name": "network-observability/network-observability-console-plugin-rhel9",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Out of support scope",
        "package_name": "workload-availability/node-healthcheck-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Out of support scope",
        "package_name": "workload-availability/node-healthcheck-operator-bundle",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Out of support scope",
        "package_name": "workload-availability/node-healthcheck-rhel9-operator",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Out of support scope",
        "package_name": "workload-availability/node-remediation-console-rhel8",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Out of support scope",
        "package_name": "workload-availability/node-remediation-console-rhel9",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Fix deferred",
        "package_name": "openshift-pipelines/pipelines-console-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/kn-eventing-integrations-aws-s3-source-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/kn-eventing-integrations-aws-sns-sink-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/kn-eventing-integrations-aws-sqs-sink-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/kn-eventing-integrations-aws-sqs-source-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/kn-eventing-integrations-log-sink-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/kn-eventing-integrations-timer-source-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Fix deferred",
        "package_name": "openshift-serverless-1/kn-eventing-integrations-transform-jsonata-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Out of support scope",
        "package_name": "openshift-service-mesh/kiali-ossmc-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Out of support scope",
        "package_name": "openshift-service-mesh/kiali-rhel8",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Out of support scope",
        "package_name": "openshift-service-mesh/kiali-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/kiali-ossmc-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/kiali-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Out of support scope",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp20/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp21/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp22/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp24/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp25/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp26/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/system-rhel7",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/system-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/system-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "rhacm2/console-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Fix deferred",
        "package_name": "advanced-cluster-security/rhacs-main-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat AMQ Broker 7",
        "fix_state": "Fix deferred",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:amq_broker:7"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-on-clouds/aoc-azure-aap-installer-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "automation-eda-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "automation-gateway",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-platform-ui",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat build of Apache Camel - HawtIO 4",
        "fix_state": "Fix deferred",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:apache_camel_hawtio:4"
      },
      {
        "product_name": "Red Hat build of Apicurio Registry 2",
        "fix_state": "Fix deferred",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:service_registry:2"
      },
      {
        "product_name": "Red Hat build of Apicurio Registry 3",
        "fix_state": "Fix deferred",
        "package_name": "apicurio/apicurio-registry-ui-rhel8",
        "cpe": "cpe:/a:redhat:apicurio_registry:3"
      },
      {
        "product_name": "Red Hat build of Apicurio Registry 3",
        "fix_state": "Fix deferred",
        "package_name": "apicurio/apicurio-registry-ui-rhel9",
        "cpe": "cpe:/a:redhat:apicurio_registry:3"
      },
      {
        "product_name": "Red Hat Build of Keycloak",
        "fix_state": "Fix deferred",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:build_keycloak:"
      },
      {
        "product_name": "Red Hat Build of Podman Desktop",
        "fix_state": "Fix deferred",
        "package_name": "podman-desktop-macos-1-0",
        "cpe": "cpe:/a:redhat:podman_desktop:1"
      },
      {
        "product_name": "Red Hat Build of Podman Desktop",
        "fix_state": "Fix deferred",
        "package_name": "podman-desktop-windows-1-0",
        "cpe": "cpe:/a:redhat:podman_desktop:1"
      },
      {
        "product_name": "Red Hat Build of Podman Desktop - Tech Preview",
        "fix_state": "Fix deferred",
        "package_name": "rhdesktop/rh-podman-desktop-ext-sandbox-rhel10",
        "cpe": "cpe:/a:redhat:podman_desktop:0"
      },
      {
        "product_name": "Red Hat Data Grid 8",
        "fix_state": "Fix deferred",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:jboss_data_grid:8"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Fix deferred",
        "package_name": "rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Fix deferred",
        "package_name": "rhdh/rhdh-hub-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Directory Server 11",
        "fix_state": "Out of support scope",
        "package_name": "redhat-ds:11/389-ds-base",
        "cpe": "cpe:/a:redhat:directory_server:11"
      },
      {
        "product_name": "Red Hat Directory Server 12",
        "fix_state": "Fix deferred",
        "package_name": "redhat-ds:12/389-ds-base",
        "cpe": "cpe:/a:redhat:directory_server:12"
      },
      {
        "product_name": "Red Hat Directory Server 13",
        "fix_state": "Out of support scope",
        "package_name": "389-ds-base",
        "cpe": "cpe:/a:redhat:directory_server:13"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Fix deferred",
        "package_name": "rhem/flightctl-ui-ocp-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Edge Manager 1",
        "fix_state": "Fix deferred",
        "package_name": "rhem/flightctl-ui-rhel9",
        "cpe": "cpe:/a:redhat:edge_manager:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "nodejs22",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "nodejs24",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "nodejs-nodemon",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mozjs60",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:20/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:20/nodejs-nodemon",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:22/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:22/nodejs-nodemon",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:24/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:24/nodejs-nodemon",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "pcs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gjs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:20/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:20/nodejs-nodemon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:22/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:22/nodejs-nodemon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:24/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:24/nodejs-nodemon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "pcs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/disk-image-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Fuse 7",
        "fix_state": "Out of support scope",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:jboss_fuse:7"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform 7",
        "fix_state": "Out of support scope",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform 8",
        "fix_state": "Fix deferred",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
        "fix_state": "Fix deferred",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:jbosseapxp"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Out of support scope",
        "package_name": "rhoai/odh-dashboard-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Out of support scope",
        "package_name": "rhoai/odh-data-science-pipelines-argo-argoexec-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Out of support scope",
        "package_name": "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Out of support scope",
        "package_name": "rhoai/odh-kf-notebook-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Out of support scope",
        "package_name": "rhoai/odh-model-registry-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Out of support scope",
        "package_name": "rhoai/odh-notebook-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/nmstate-console-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-agent-installer-ui-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-console",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-console-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-monitoring-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-networking-console-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/jetbrains-ide-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/openvsx-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Fix deferred",
        "package_name": "rhosdt/tempo-jaeger-query-rhel9",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Fix deferred",
        "package_name": "openshift-gitops-1/argocd-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Fix deferred",
        "package_name": "openshift-gitops-1/argocd-rhel9",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Fix deferred",
        "package_name": "openshift-gitops-1/console-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/kubevirt-console-plugin-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat Process Automation 7",
        "fix_state": "Out of support scope",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Out of support scope",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Single Sign-On 7",
        "fix_state": "Out of support scope",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Not affected",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      },
      {
        "product_name": "streams for Apache Kafka 2",
        "fix_state": "Fix deferred",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:amq_streams:2"
      },
      {
        "product_name": "streams for Apache Kafka 3",
        "fix_state": "Fix deferred",
        "package_name": "brace-expansion",
        "cpe": "cpe:/a:redhat:amq_streams:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33750\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33750\nhttps://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L107-L113\nhttps://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L184\nhttps://github.com/juliangruber/brace-expansion/commit/311ac0d54994158c0a384e286a7d6cbb17ee8ed5\nhttps://github.com/juliangruber/brace-expansion/commit/7fd684f89fdde3549563d0a6522226a9189472a2\nhttps://github.com/juliangruber/brace-expansion/commit/b9cacd9e55e7a1fa588fe4b7bb1159d52f1d902a\nhttps://github.com/juliangruber/brace-expansion/issues/98\nhttps://github.com/juliangruber/brace-expansion/pull/95\nhttps://github.com/juliangruber/brace-expansion/pull/96\nhttps://github.com/juliangruber/brace-expansion/pull/97\nhttps://github.com/juliangruber/brace-expansion/security/advisories/GHSA-f886-m6hf-6m8v"
    ],
    "name": "CVE-2026-33750",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-30T17:28:41Z",
    "bugzilla": {
      "description": "gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment",
      "id": "2450624",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450624"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-191",
    "details": [
      "A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.",
      "A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service."
    ],
    "statement": "This issue marked as Important severity due to its remote, pre-authentication reachability and its impact on a critical DTLS handshake parsing path. The vulnerability can be triggered by an unauthenticated attacker sending crafted DTLS handshake fragments, requiring no prior access or interaction. It leads to an out-of-bounds read caused by an integer underflow in fragment reassembly, operating entirely on attacker-controlled input. Such flaws in low-level protocol parsing are particularly serious, as they may result in disclosure of sensitive process memory, including cryptographic or session-related data, and can also cause reliable application crashes leading to denial of service. Given that DTLS is commonly used in network-facing services such as VPNs and real-time communication systems, the exposure surface is broad. The combination of unauthenticated remote exploitation, memory safety violation, and potential confidentiality and availability impact justifies classifying this issue as high severity rather than moderate.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20613",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gnutls-0:3.8.10-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26409",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gnutls-0:3.8.9-9.el10_0.19"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34372",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gnutls-0:3.3.29-9.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41921",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gnutls-0:3.7.6-21.el9_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32962",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gnutls-0:3.8.3-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30004",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gnutls-0:3.8.3-6.el9_6.4"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36004",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1782951051"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36005",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1782951012"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36006",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782951244"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:13274",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gnutls-main-3.8.13-1.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33845\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33845"
    ],
    "name": "CVE-2026-33845",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-04T08:53:59Z",
    "bugzilla": {
      "description": "gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly",
      "id": "2450625",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450625"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-130",
    "details": [
      "A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.",
      "A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption."
    ],
    "statement": "This vulnerability should be classified as an important flaw rather than moderate because it exposes a pre-authentication, remotely reachable heap buffer overflow in the DTLS handshake processing path, which is part of the core protocol handling logic and commonly exposed in network-facing services. The flaw enables an attacker to inject controlled data at attacker-chosen offsets and sizes beyond allocated heap boundaries by exploiting inconsistent message_length handling across fragments, effectively creating a constrained but meaningful heap write primitive. Unlike benign memory safety bugs, this condition is deterministically triggerable with a small number of crafted packets and no environmental dependencies for denial-of-service, and it targets a long-lived parsing state where memory corruption can affect adjacent heap structures. Even if reliable code execution requires additional heap manipulation or layout knowledge, the combination of remote reachability, lack of authentication, controlled memory corruption capability, and trivial crashability significantly elevates the risk profile beyond moderate severity. In real-world deployments, such primitives are often sufficient to enable heap grooming and exploitation chains, particularly in services that repeatedly process attacker-controlled input, making this a materially important security flaw.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20613",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gnutls-0:3.8.10-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26409",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gnutls-0:3.8.9-9.el10_0.19"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34372",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gnutls-0:3.3.29-9.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41921",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gnutls-0:3.7.6-21.el9_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32962",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gnutls-0:3.8.3-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30004",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gnutls-0:3.8.3-6.el9_6.4"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36004",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1782951051"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36005",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1782951012"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36006",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782951244"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:13274",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gnutls-main-3.8.13-1.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33846\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33846"
    ],
    "name": "CVE-2026-33846",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-04T13:07:30Z",
    "bugzilla": {
      "description": "httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions",
      "id": "2464953",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464953"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "Out-of-bounds Read vulnerability in mod_proxy_ajp of \nApache HTTP Server.\nThis issue affects Apache HTTP Server: through 2.4.66.\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.",
      "A flaw was found in the mod_proxy_ajp module of httpd. When processing AJP (Apache JServ Protocol) messages, the AJP getter functions attempt to read data beyond the allocated buffer size, allowing an attacker or a malformed request to cause an out-of-bounds read. This issue leads to a denial of service."
    ],
    "statement": "To exploit this issue, the Apache HTTP Server must be configured to connect to an untrusted or compromised AJP backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity.\nThis flaw only affects configurations with mod_proxy_ajp loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.",
    "affected_release": [
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el7jbcs"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21433",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47046",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "httpd-0:2.4.63-1.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22140",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "httpd:2.4-8100020260519200905.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36846",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "httpd:2.4-8040020260702193120.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36846",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "httpd:2.4-8040020260702193120.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36831",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "httpd:2.4-8060020260702195216.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36831",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "httpd:2.4-8060020260702195216.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36373",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "httpd:2.4-8080020260702200145.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36373",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "httpd:2.4-8080020260702200145.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21391",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.1"
      },
      {
        "product_name": "Red Hat JBoss Core Services 2.4.62.SP4",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27201",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "mod_proxy_ajp.so"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13938",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.67-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33857\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33857\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-33857",
    "mitigation": {
      "value": "Disabling mod_proxy_ajp and restarting httpd will mitigate this flaw.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-13T20:46:43Z",
    "bugzilla": {
      "description": "ImageMagick: Magick.NET: ImageMagick: Denial of Service via out-of-bounds write in XML parsing",
      "id": "2458026",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458026"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-805",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.",
      "A flaw was found in ImageMagick. When processing a specially crafted XML file, a remote attacker could exploit an out-of-bounds write vulnerability. This could lead to a denial of service, making the affected program unavailable."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33899\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33899\nhttps://github.com/ImageMagick/ImageMagick/commit/ae679e2fd19ec656bfab9f822ae4cf06bf91604d\nhttps://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cr67-pvmx-2pp2\nhttps://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"
    ],
    "name": "CVE-2026-33899",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-13T20:50:19Z",
    "bugzilla": {
      "description": "ImageMagick: Magick.NET: ImageMagick: Denial of Service via integer truncation in viff encoder",
      "id": "2458020",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458020"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write, potentially causing a crash. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.",
      "A flaw was found in ImageMagick, a software suite for editing and manipulating digital images. This vulnerability, an integer truncation/wraparound issue within the viff encoder on 32-bit builds, could lead to an out-of-bounds heap write. An attacker could exploit this by providing a specially crafted image file, potentially causing the application to crash and resulting in a Denial of Service (DoS)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33900\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33900\nhttps://github.com/ImageMagick/ImageMagick/commit/d27b840a61b322419a66d0d192ff56d52498148d\nhttps://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v67w-737x-v2c9\nhttps://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"
    ],
    "name": "CVE-2026-33900",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-13T20:56:12Z",
    "bugzilla": {
      "description": "ImageMagick: Magick.NET: ImageMagick: Denial of Service due to heap buffer overflow in MVG decoder",
      "id": "2458023",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458023"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.",
      "A flaw was found in ImageMagick. A remote attacker could exploit a heap buffer overflow vulnerability in the MVG decoder by processing a specially crafted image file. This vulnerability allows for an out-of-bounds write, which could lead to a Denial of Service (DoS) for the affected system."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33901\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33901\nhttps://github.com/ImageMagick/ImageMagick/commit/4c72003e9e54a4ebaa938d239e75f5d285527ebe\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x9h5-r9v2-vcww\nhttps://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"
    ],
    "name": "CVE-2026-33901",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-13T20:59:47Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via deeply nested expression in FX parser",
      "id": "2458040",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458040"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-770",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a stack overflow vulnerability in ImageMagick's FX expression parser allows an attacker to crash the process by providing a deeply nested expression. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.",
      "A flaw was found in ImageMagick, a software used for editing and manipulating digital images. An attacker can exploit this vulnerability by providing a deeply nested expression to ImageMagick's FX expression parser. This can lead to a stack overflow, causing the process to crash and resulting in a Denial of Service (DoS)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33902\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33902\nhttps://github.com/ImageMagick/ImageMagick/commit/d3c0a37485314c5ccef72efb18f3847cd53868ba\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f4qm-vj5j-9xpw\nhttps://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"
    ],
    "name": "CVE-2026-33902",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-13T21:02:58Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of service via out-of-bounds read in -sample operation",
      "id": "2458055",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458055"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the -sample operation has an out of bounds read when an specific offset is set through the `sample:offset` define that could lead to an out of bounds read. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.",
      "A flaw was found in ImageMagick. This vulnerability allows a local user to cause a denial of service (DoS) by providing a specially crafted image that exploits an out-of-bounds read during the -sample operation when a specific offset is set through the `sample:offset` define. This can lead to application instability or crashes."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33905\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33905\nhttps://github.com/ImageMagick/ImageMagick/commit/cca607366fb38c2dde019a9088b8415ffba3a835\nhttps://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pcvx-ph33-r5vv\nhttps://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"
    ],
    "name": "CVE-2026-33905",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-13T21:06:42Z",
    "bugzilla": {
      "description": "ImageMagick: Magick.NET: ImageMagick: Denial of Service via deeply nested XML file processing",
      "id": "2458041",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458041"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-776",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyXMLTree()` function; however, this process is executed recursively with no depth limit imposed. When Magick processes an XML file with deeply nested structures, it will exhaust the stack memory, resulting in a Denial of Service (DoS) attack. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.",
      "A flaw was found in ImageMagick, a free and open-source software for editing and manipulating digital images. When ImageMagick processes an XML file with deeply nested structures, the `DestroyXMLTree()` function, which frees memory, is executed recursively without a depth limit. This can lead to the exhaustion of stack memory, allowing a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted XML file."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33908\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33908\nhttps://github.com/ImageMagick/ImageMagick/commit/ccdc01180276aa2cb3d4a32a611aa4f417061cd8\nhttps://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fwvm-ggf6-2p4x\nhttps://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"
    ],
    "name": "CVE-2026-33908",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-13T21:50:18Z",
    "bugzilla": {
      "description": "jq: unbounded Recursion in jv_setpath() / jv_getpath() / delpaths_sorted()",
      "id": "2458038",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458038"
    },
    "cvss3": {
      "cvss3_base_score": "6.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-674",
    "details": [
      "jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects the JSON parser, not runtime path operations where arrays can be programmatically constructed to arbitrary lengths. The impact is denial of service (unrecoverable crash) affecting any application or service that processes untrusted JSON input through jq's setpath, getpath, or delpaths builtins. This issue has been addressed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f.",
      "A flaw was found in jq, a command line JSON processor. Processing a crafted JSON document, specifically when a large array is used as a path argument to the `jv_setpath`, `jv_getpath` and `delpaths_sorted` functions can lead to an uncontrolled recursion and exhausts the call stack, causing an application crash and resulting in a denial of service."
    ],
    "statement": "To exploit this issue, an attacker needs to supply a crafted JSON input to be processed by jq with the `setpath`, `getpath` or `delpaths` builtins. This allows the attacker to cause an application crash with no other security impact. Due to these reasons, this flaw has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8579",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.1-3.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33947\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33947\nhttps://github.com/jqlang/jq/commit/fb59f1491058d58bdc3e8dd28f1773d1ac690a1f\nhttps://github.com/jqlang/jq/security/advisories/GHSA-xwrw-4f8h-rjvg"
    ],
    "name": "CVE-2026-33947",
    "mitigation": {
      "value": "Do not process untrusted input with the jq command line JSON processor.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-13T23:51:04Z",
    "bugzilla": {
      "description": "jq: jq: Input validation bypass via embedded NUL bytes allows parser differential attacks",
      "id": "2458085",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458085"
    },
    "cvss3": {
      "cvss3_base_score": "3.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-170",
    "details": [
      "jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte count from fgets(), causing it to truncate input at the first NUL byte and parse only the preceding prefix. This enables an attacker to craft input with a benign JSON prefix before a NUL byte followed by malicious trailing data, where jq validates only the prefix as valid JSON while silently discarding the suffix. Workflows relying on jq to validate untrusted JSON before forwarding it to downstream consumers are susceptible to parser differential attacks, as those consumers may process the full input including the malicious trailing bytes. This issue has been patched by commit 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b.",
      "A flaw was found in jq, a command-line JSON processor. This vulnerability allows a remote attacker to bypass input validation by crafting malicious JSON input containing embedded null (NUL) bytes. Due to incorrect handling of input buffer lengths, jq truncates the input at the first NUL byte, validating only the benign prefix and silently discarding any malicious data that follows. This can lead to parser differential attacks where downstream systems, relying on jq for validation, may process the full, unvalidated input, potentially leading to unexpected behavior or security compromises."
    ],
    "statement": "This vulnerability in `jq` allows an attacker to bypass input validation by embedding NUL bytes in JSON input. This is relevant in Red Hat environments where `jq` is used to validate untrusted JSON before it is processed by other tools, potentially leading to parser differential attacks and unexpected behavior in downstream systems. The `jq` command line tool is not exposed to the network in default configurations of Red Hat products.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8579",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.1-3.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33948\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33948\nhttps://github.com/jqlang/jq/commit/6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b\nhttps://github.com/jqlang/jq/security/advisories/GHSA-32cx-cvvh-2wj9"
    ],
    "name": "CVE-2026-33948",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-30T21:42:27Z",
    "bugzilla": {
      "description": "FreeRDP: FreeRDP: Denial of Service via specially crafted Remote Desktop Protocol messages",
      "id": "2453220",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453220"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_upgrade() detects a mismatch via progressive_rfx_quant_cmp_equal() but only emits WLog_WARN, execution continues. The wrapped value (247) is used as a shift exponent, causing undefined behavior and an approximately 80 billion iteration loop (CPU DoS). This issue has been patched in version 3.24.2.",
      "A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP). A remote attacker could exploit this vulnerability by sending a specially crafted RDP message. This can lead to an undefined behavior where a wrapped value is used as a shift exponent, causing an approximately 80 billion iteration loop. This results in a Denial of Service (DoS) due to excessive CPU utilization."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8458",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "freerdp-2:3.10.3-5.el10_1.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19033",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freerdp-2:3.10.3-12.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11333",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freerdp-2:3.10.3-3.el10_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8945",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "freerdp-2:2.11.7-7.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11651",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "freerdp-2:2.0.0-46.rc4.el8_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11649",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "freerdp-2:2.2.0-13.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11649",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "freerdp-2:2.2.0-13.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12388",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12388",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12388",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12359",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12359",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19349",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-7.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8457",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-1.el9_7.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11332",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "freerdp-2:2.4.1-3.el9_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11336",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freerdp-2:2.4.1-6.el9_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10709",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "freerdp-2:2.11.2-1.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9656",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freerdp-2:2.11.7-1.el9_6.8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33983\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33983\nhttps://github.com/FreeRDP/FreeRDP/commit/78188ab479c8e6eb9ba2475b3732c76b4bbe5425\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4gfm-4p52-h478"
    ],
    "name": "CVE-2026-33983",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-30T21:42:57Z",
    "bugzilla": {
      "description": "FreeRDP: FreeRDP: Heap buffer overflow allows arbitrary code execution via crafted pixel data",
      "id": "2453219",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453219"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.",
      "A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. A remote attacker could exploit a heap buffer overflow vulnerability in the `resize_vbar_entry()` function. This occurs when an error in buffer resizing leads to attacker-controlled pixel data being written into an undersized memory buffer. Successful exploitation could result in arbitrary code execution."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8458",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "freerdp-2:3.10.3-5.el10_1.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19033",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freerdp-2:3.10.3-12.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11333",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freerdp-2:3.10.3-3.el10_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8945",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "freerdp-2:2.11.7-7.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11651",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "freerdp-2:2.0.0-46.rc4.el8_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11649",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "freerdp-2:2.2.0-13.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11649",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "freerdp-2:2.2.0-13.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12388",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12388",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12388",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12359",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12359",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19349",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-7.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8457",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-1.el9_7.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11332",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "freerdp-2:2.4.1-3.el9_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11336",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freerdp-2:2.4.1-6.el9_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10709",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "freerdp-2:2.11.2-1.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9656",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freerdp-2:2.11.7-1.el9_6.8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33984\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33984\nhttps://github.com/FreeRDP/FreeRDP/commit/dc7fdb165095139be779a4000199bc1706b06ad5\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8469-2xcx-frf6"
    ],
    "name": "CVE-2026-33984",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-30T21:43:13Z",
    "bugzilla": {
      "description": "FreeRDP: FreeRDP: Information disclosure via heap memory out of bounds read",
      "id": "2453217",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453217"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2.",
      "A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. A remote attacker could exploit a vulnerability where pixel data from adjacent heap memory is rendered to the screen. This can lead to the disclosure of sensitive data to the attacker."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16014",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "freerdp-2:3.10.3-5.el10_1.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19142",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freerdp-2:3.10.3-12.el10_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20605",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freerdp-2:3.10.3-3.el10_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20546",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "freerdp-0:2.1.1-5.el7_9.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16019",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "freerdp-2:2.11.7-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19811",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "freerdp-2:2.2.0-14.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16814",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "freerdp-2:2.2.0-7.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16777",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "freerdp-2:2.2.0-12.el8_8.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16482",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-1.el9_7.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19358",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freerdp-2:2.11.7-7.el9_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16485",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "freerdp-2:2.4.1-3.el9_0.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16483",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freerdp-2:2.4.1-6.el9_2.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16866",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "freerdp-2:2.11.2-1.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16865",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freerdp-2:2.11.7-1.el9_6.10"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "freerdp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33985\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33985\nhttps://github.com/FreeRDP/FreeRDP/commit/c49d1ad43b8c7b32794d0250f2623c2dccd7ef25\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x6gr-8p7h-5h85"
    ],
    "name": "CVE-2026-33985",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-31T01:36:51Z",
    "bugzilla": {
      "description": "moby: docker: github.com/moby/moby: Moby: Privilege validation bypass during plugin installation",
      "id": "2453277",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453277"
    },
    "cvss3": {
      "cvss3_base_score": "8.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-266",
    "details": [
      "Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.",
      "A flaw was found in Moby, an open-source container framework. This vulnerability allows for a privilege validation bypass during `docker plugin install`. Due to an error in the daemon's privilege comparison logic, the system may incorrectly accept a plugin's requested privileges that differ from those approved by the user. This could lead to unauthorized privilege escalation for installed plugins."
    ],
    "statement": "An important flaw in Moby, an open-source container framework, allows for a privilege validation bypass during `docker plugin install`. This issue stems from an error in the daemon's privilege comparison logic, which could lead to unauthorized privilege escalation for installed plugins. Red Hat products that leverage Moby and allow Docker plugin installation are affected.",
    "affected_release": [
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21769",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22347",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23345",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118"
      }
    ],
    "package_state": [
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-service-8-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-service-9-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-grafana-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-console",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/hostpath-provisioner-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33997\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33997\nhttps://github.com/moby/moby/releases/tag/docker-v29.3.1\nhttps://github.com/moby/moby/security/advisories/GHSA-pxq6-2prw-chj9"
    ],
    "name": "CVE-2026-33997",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-23T14:11:12Z",
    "bugzilla": {
      "description": "xorg: xwayland: X.Org X server: Denial of Service via integer underflow in XKB compatibility map handling",
      "id": "2451106",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451106"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-191",
    "details": [
      "A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.",
      "A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts."
    ],
    "statement": "An Important integer underflow vulnerability exists in the X.Org X server's XKB compatibility map handling. This flaw allows an attacker with local or remote X11 server access to trigger a buffer read overrun, leading to memory-safety violations and potential denial of service. Red Hat Enterprise Linux systems utilizing the X.Org X server in graphical environments are affected.",
    "acknowledgement": "Red Hat would like to thank Jan-Niklas Sohn (TrendAI Zero Day Initiative) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11352",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19125",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20563",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23496",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "tigervnc-0:1.1.0-25.el6_10.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20590",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-34.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22456",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11656",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-20.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11692",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-0:1.20.11-28.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13414",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "tigervnc-0:1.15.0-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21715",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23254",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21715",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23254",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24341",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24341",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21712",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21742",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-18.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23255",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21712",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21742",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-18.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23255",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10739",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-6.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11369",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11388",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-33.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19342",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-7.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19343",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-34.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19344",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20562",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-5.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21699",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "xorg-x11-server-0:1.20.11-13.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21741",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "tigervnc-0:1.11.0-22.el9_0.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20547",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20557",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-20.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20576",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20555",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "xorg-x11-server-0:1.20.11-28.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20560",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20575",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20558",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-33.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20561",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22424",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-10.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-33999\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33999"
    ],
    "name": "CVE-2026-33999",
    "mitigation": {
      "value": "To mitigate this issue, restrict access to the X11 server. For remote access, disable X11 forwarding in SSH configurations if not required. Edit `/etc/ssh/sshd_config` and set `X11Forwarding no`. After modifying the configuration, restart the `sshd` service using `systemctl restart sshd`. Disabling X11 forwarding may impact remote graphical applications.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-05T14:01:15Z",
    "bugzilla": {
      "description": "xwayland: xorg: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing.",
      "id": "2451107",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451107"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or remotely, can exploit this without user interaction. This could lead to the disclosure of memory contents or cause a denial of service by crashing the server.",
      "A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or remotely, can exploit this without user interaction. This could lead to the disclosure of memory contents or cause a denial of service by crashing the server."
    ],
    "statement": "This out-of-bounds read vulnerability in the X.Org X server's XKB geometry processing could allow an attacker to leak memory contents or cause a denial of service. Exploitation requires an attacker to establish a connection to the X11 server, either locally or through forwarded remote sessions. Red Hat Enterprise Linux systems with a graphical environment enabled are potentially affected.",
    "acknowledgement": "Red Hat would like to thank Jan-Niklas Sohn (TrendAI Zero Day Initiative) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20563",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23496",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "tigervnc-0:1.1.0-25.el6_10.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20590",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-34.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22456",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21715",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23254",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21715",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23254",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24341",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24341",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21712",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21742",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-18.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23255",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21712",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21742",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-18.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23255",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19342",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-7.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20562",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-5.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21699",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "xorg-x11-server-0:1.20.11-13.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21741",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "tigervnc-0:1.11.0-22.el9_0.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20547",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20557",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-20.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20576",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20555",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "xorg-x11-server-0:1.20.11-28.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20560",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20575",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20558",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-33.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20561",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22424",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-10.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "xorg-x11-server-Xwayland",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "tigervnc",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "xorg-x11-server-Xwayland",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "xorg-x11-server-Xwayland",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34000\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34000"
    ],
    "name": "CVE-2026-34000",
    "mitigation": {
      "value": "To mitigate this vulnerability, restrict access to the X11 server. On systems where a graphical environment is not required, consider disabling the X server entirely by setting the default system target to multi-user mode. For systems requiring the X server, ensure that X11 forwarding is disabled in SSH configurations if not explicitly needed, and restrict direct X11 connections to trusted users and networks through firewall rules. If changes are made to SSH configuration, the `sshd` service must be restarted. If the default system target is changed, a system reboot is required.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-23T14:14:42Z",
    "bugzilla": {
      "description": "xorg: xwayland: X.Org X server: Use-after-free vulnerability leads to server crash and potential memory corruption",
      "id": "2451109",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451109"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.",
      "A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system."
    ],
    "statement": "Important: This use-after-free vulnerability in the X.Org X server's XSYNC fence triggering logic can lead to a server crash and potential memory corruption. Exploitation requires an attacker to have access to the X11 server, typically limited to local users or trusted remote connections. Systems not running the X.Org X server are not affected.",
    "acknowledgement": "Red Hat would like to thank Jan-Niklas Sohn (TrendAI Zero Day Initiative) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11352",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19125",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20563",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23496",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "tigervnc-0:1.1.0-25.el6_10.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20590",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-34.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22456",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11656",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-20.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11692",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-0:1.20.11-28.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13414",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "tigervnc-0:1.15.0-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21715",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23254",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21715",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23254",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24341",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24341",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21712",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21742",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-18.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23255",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21712",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21742",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-18.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23255",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10739",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-6.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11369",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11388",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-33.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19342",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-7.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19343",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-34.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19344",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20562",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-5.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21699",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "xorg-x11-server-0:1.20.11-13.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21741",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "tigervnc-0:1.11.0-22.el9_0.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20547",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20557",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-20.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20576",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20555",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "xorg-x11-server-0:1.20.11-28.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20560",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20575",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20558",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-33.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20561",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22424",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-10.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34001\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34001"
    ],
    "name": "CVE-2026-34001",
    "mitigation": {
      "value": "To mitigate this issue, restrict access to the X11 server to trusted users and networks. If the X.Org X server is not required, consider disabling or uninstalling it. For environments where the X server is essential, running X applications within a sandboxed environment can help reduce the attack surface.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-05T14:01:46Z",
    "bugzilla": {
      "description": "xorg: xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling",
      "id": "2451112",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451112"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-805",
    "details": [
      "A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory boundaries. This can lead to the exposure of sensitive information or cause the server to crash, resulting in a denial of service.",
      "A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory boundaries. This can lead to the exposure of sensitive information or cause the server to crash, resulting in a denial of service."
    ],
    "statement": "Moderate: This out-of-bounds read vulnerability in the X.Org X server's XKB modifier map handling could lead to information disclosure or service crashes. An attacker with access to the X11 server can trigger this without user interaction. This affects systems running the X.Org X server.",
    "acknowledgement": "Red Hat would like to thank Jan-Niklas Sohn (TrendAI Zero Day Initiative) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20563",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23496",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "tigervnc-0:1.1.0-25.el6_10.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20590",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-34.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22456",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21715",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23254",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21715",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23254",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24341",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24341",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21712",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21742",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-18.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23255",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21712",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21742",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-18.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23255",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20562",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-5.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21699",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "xorg-x11-server-0:1.20.11-13.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21741",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "tigervnc-0:1.11.0-22.el9_0.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20547",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20557",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-20.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20576",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20555",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "xorg-x11-server-0:1.20.11-28.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20560",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20575",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20558",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-33.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20561",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22424",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-10.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "xorg-x11-server-Xwayland",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "tigervnc",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "xorg-x11-server-Xwayland",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "tigervnc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "xorg-x11-server-Xwayland",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "moderate"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34002\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34002"
    ],
    "name": "CVE-2026-34002",
    "mitigation": {
      "value": "To mitigate this vulnerability, restrict access to the X11 server. If the X.Org X server is not required on a system, consider disabling or uninstalling it. For systems where the X server is necessary, ensure that access is limited to trusted users and networks. This can involve configuring `xhost` or implementing firewall rules to restrict connections to the X server. Any changes to X server configuration or service status may require a restart of the X server for the mitigation to take effect, which will impact active graphical sessions.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-23T14:18:00Z",
    "bugzilla": {
      "description": "xorg: xwayland: X.Org X server: Information exposure and denial of service via out-of-bounds memory access",
      "id": "2451113",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451113"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of Service (DoS). In certain configurations, higher impact outcomes may be possible.",
      "A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of Service (DoS). In certain configurations, higher impact outcomes may be possible."
    ],
    "statement": "An Important out-of-bounds memory access vulnerability exists in the X.Org X server's XKB key types request validation. This flaw could lead to information exposure or a server crash and requires a specially crafted request to trigger. Systems running a graphical environment are potentially affected, with higher impact outcomes possible in certain configurations.",
    "acknowledgement": "Red Hat would like to thank Jan-Niklas Sohn (TrendAI Zero Day Initiative) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11352",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19125",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20563",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23496",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "tigervnc-0:1.1.0-25.el6_10.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20590",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-34.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22456",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11656",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-20.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11692",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-0:1.20.11-28.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13414",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "tigervnc-0:1.15.0-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21715",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23254",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21715",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-4.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23254",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24341",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24341",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21716",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21718",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "xorg-x11-server-0:1.20.11-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21712",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21742",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-18.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23255",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21712",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21742",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-18.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23255",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10739",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-6.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11369",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11388",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-33.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19342",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-7.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19343",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-34.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19344",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20562",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-5.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21699",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "xorg-x11-server-0:1.20.11-13.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21741",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "tigervnc-0:1.11.0-22.el9_0.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20547",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20557",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-20.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20576",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20555",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "xorg-x11-server-0:1.20.11-28.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20560",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20575",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20558",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-33.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20561",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22424",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-10.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34003\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34003"
    ],
    "name": "CVE-2026-34003",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-04T12:54:54Z",
    "bugzilla": {
      "description": "httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check",
      "id": "2464952",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464952"
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-170",
    "details": [
      "Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.\nThis issue affects Apache HTTP Server: through 2.4.66.\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.",
      "A flaw was found in the mod_proxy_ajp module of httpd. When processing AJP (Apache JServ Protocol) messages, the server fails to properly check if a string is null-terminated before attempting to read it, allowing an attacker or a malformed request to cause a heap-based buffer over-read. This issue potentially leads to memory disclosure and a denial of service."
    ],
    "statement": "To exploit this issue, the Apache HTTP Server must be configured to connect to an untrusted or compromised AJP backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity.\nThis flaw only affects configurations with mod_proxy_ajp loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.",
    "affected_release": [
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el7jbcs"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21433",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47046",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "httpd-0:2.4.63-1.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22140",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "httpd:2.4-8100020260519200905.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36846",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "httpd:2.4-8040020260702193120.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36846",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "httpd:2.4-8040020260702193120.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36831",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "httpd:2.4-8060020260702195216.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36831",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "httpd:2.4-8060020260702195216.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36373",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "httpd:2.4-8080020260702200145.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36373",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "httpd:2.4-8080020260702200145.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21391",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.1"
      },
      {
        "product_name": "Red Hat JBoss Core Services 2.4.62.SP4",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27201",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "mod_proxy_ajp.so"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13938",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.67-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34032\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34032\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-34032",
    "mitigation": {
      "value": "Disabling mod_proxy_ajp and restarting httpd will mitigate this flaw.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-31T01:36:48Z",
    "bugzilla": {
      "description": "Moby: Moby: Authorization bypass vulnerability",
      "id": "2453278",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453278"
    },
    "cvss3": {
      "cvss3_base_score": "8.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-807",
    "details": [
      "Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.",
      "A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container environment. The bypass of these plugins can lead to unauthorized operations and potential compromise of the system's integrity and confidentiality."
    ],
    "affected_release": [
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21769",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753"
      },
      {
        "product_name": "Multicluster Global Hub 1.7.0",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24503",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.7::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22347",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23345",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118"
      }
    ],
    "package_state": [
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-agent-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-controller-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-service-8-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-service-9-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/must-gather-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-grafana-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/prometheus-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Affected",
        "package_name": "rhceph-ci/grafana",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift3/ose-console",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-console",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "openshift-virtualization/hostpath-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "openshift-virtualization/hostpath-provisioner-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "openshift-virtualization/hostpath-provisioner-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "openshift-virtualization/hyperconverged-cluster-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "openshift-virtualization/hyperconverged-cluster-webhook-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34040\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34040\nhttps://github.com/moby/moby/releases/tag/docker-v29.3.1\nhttps://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2"
    ],
    "name": "CVE-2026-34040",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-04T12:39:42Z",
    "bugzilla": {
      "description": "httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data()",
      "id": "2464940",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464940"
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-126",
    "details": [
      "Buffer Over-read vulnerability in Apache HTTP Server.\nThis issue affects Apache HTTP Server: through 2.4.66.\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.",
      "A flaw was found in the mod_proxy_ajp module of httpd. When processing AJP (Apache JServ Protocol) messages, the ajp_parse_data function attempts to read data beyond the allocated buffer size, allowing an attacker or a malformed request to cause a heap-based buffer over-read. This issue potentially leads to memory disclosure and a denial of service."
    ],
    "statement": "To exploit this issue, the Apache HTTP Server must be configured to connect to an untrusted or compromised AJP backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity.\nThis flaw only affects configurations with mod_proxy_ajp loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.",
    "affected_release": [
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el7jbcs"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21433",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47046",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "httpd-0:2.4.63-1.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22140",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "httpd:2.4-8100020260519200905.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36846",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "httpd:2.4-8040020260702193120.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36846",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "httpd:2.4-8040020260702193120.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36831",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "httpd:2.4-8060020260702195216.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36831",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "httpd:2.4-8060020260702195216.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36373",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "httpd:2.4-8080020260702200145.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36373",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "httpd:2.4-8080020260702200145.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21391",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.1"
      },
      {
        "product_name": "Red Hat JBoss Core Services 2.4.62.SP4",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27201",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "mod_proxy_ajp.so"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13938",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.67-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34059\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34059\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-34059",
    "mitigation": {
      "value": "Disabling mod_proxy_ajp and restarting httpd will mitigate this flaw.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-07T21:27:45Z",
    "bugzilla": {
      "description": "flatpak: Flatpak: Arbitrary code execution via crafted symlinks in sandbox-expose options",
      "id": "2456276",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456276"
    },
    "cvss3": {
      "cvss3_base_score": "9.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-59",
    "details": [
      "Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.",
      "A flaw was found in Flatpak, a Linux application sandboxing and distribution framework. A malicious application could exploit this by using specially crafted symlinks within the sandbox-expose options of the Flatpak portal. This allows the application to access arbitrary host files and potentially achieve code execution on the host system, bypassing the intended security sandbox."
    ],
    "statement": "This Important flaw in Flatpak allows a malicious Flatpak application to escape its sandbox and achieve arbitrary code execution on the host system. By exploiting specially crafted symlinks within the `sandbox-expose` options, the integrity of the Flatpak sandboxing mechanism, a critical security feature in Red Hat environments, is compromised.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21757",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "flatpak-0:1.16.0-9.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23420",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "flatpak-0:1.16.0-5.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35843",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "flatpak-0:1.12.9-3.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21756",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "flatpak-0:1.12.9-4.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30901",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "flatpak-0:1.12.9-2.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30901",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "flatpak-0:1.12.9-2.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25381",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "flatpak-0:1.12.9-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25381",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "flatpak-0:1.12.9-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25068",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "flatpak-0:1.12.9-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25068",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "flatpak-0:1.12.9-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21755",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "flatpak-0:1.12.9-4.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23419",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "flatpak-0:1.12.7-5.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23417",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "flatpak-0:1.12.9-3.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23418",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "flatpak-0:1.12.9-4.el9_6.1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34078\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34078\nhttps://github.com/flatpak/flatpak/security/advisories/GHSA-cc2q-qc34-jprg"
    ],
    "name": "CVE-2026-34078",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-07T21:29:44Z",
    "bugzilla": {
      "description": "flatpak: Flatpak: Arbitrary file deletion on host via improper cache file path validation",
      "id": "2456284",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456284"
    },
    "cvss3": {
      "cvss3_base_score": "6.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-22",
    "details": [
      "Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps  to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.",
      "A flaw was found in Flatpak, a Linux application sandboxing and distribution framework. The caching mechanism for ld.so (dynamic linker/loader) improperly removes outdated cache files without adequately verifying that the application-controlled path to the outdated cache is within the designated cache directory. This vulnerability allows Flatpak applications to delete arbitrary files on the host system, potentially leading to system instability or data loss."
    ],
    "statement": "The CVE has been rated as moderate by Red Hat for multiple reasons. The vulnerability can only be exploited by executing a malicious Flatpak application on the local system. The attacker must already have the ability to: provide a Flatpak package to the victim, and have the victim install/run it locally. The attacker must execute a Flatpak application under a valid user account; hence privilage required is low. A victim must: install,trust,or launch the malicious Flatpak application.\nWithout user interaction, the exploit cannot occur because the attacker cannot independently trigger execution of the malicious package.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21757",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "flatpak-0:1.16.0-9.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23420",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "flatpak-0:1.16.0-5.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35843",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "flatpak-0:1.12.9-3.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21756",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "flatpak-0:1.12.9-4.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30901",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "flatpak-0:1.12.9-2.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30901",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "flatpak-0:1.12.9-2.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25381",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "flatpak-0:1.12.9-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25381",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "flatpak-0:1.12.9-1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25068",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "flatpak-0:1.12.9-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25068",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "flatpak-0:1.12.9-1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21755",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "flatpak-0:1.12.9-4.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23419",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "flatpak-0:1.12.7-5.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23417",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "flatpak-0:1.12.9-3.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23418",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "flatpak-0:1.12.9-4.el9_6.1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34079\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34079\nhttps://github.com/flatpak/flatpak/security/advisories/GHSA-p29x-r292-46pp"
    ],
    "name": "CVE-2026-34079",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-09T00:00:00Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.",
      "id": "2481881",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
      "A flaw was found in OpenSSL. An integer truncation vulnerability in the ASN.1 decoder can occur when processing a crafted DER-encoded ASN.1 structure with a primitive element exceeding 2 gigabytes. A remote attacker could exploit this to cause a heap buffer over-read. This may lead to an application crash, resulting in a Denial of Service (DoS), or potentially disclose sensitive information by loading memory contents beyond the input buffer. This issue primarily affects 64-bit Unix and Unix-like platforms."
    ],
    "statement": "This Low impact vulnerability in OpenSSL's ASN.1 decoder affects 64-bit Unix-like platforms, where processing a crafted DER-encoded ASN.1 structure exceeding 2 gigabytes can lead to a heap buffer over-read. This may result in application crashes (Denial of Service) or unintended memory exposure. Red Hat products are only affected if they process untrusted, excessively large ASN.1 input using OpenSSL's d2i_* decoding functions.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25237",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "openssl-1:3.5.5-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25239",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25239",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-4.el9_8"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34102",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1782890503"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Under investigation",
        "package_name": "jbcs-httpd24-openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Under investigation",
        "package_name": "jbcs-openssl-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Under investigation",
        "package_name": "jws-optional-native-components-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7",
        "fix_state": "Under investigation",
        "package_name": "jws-optional-native-components-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34180\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34180"
    ],
    "name": "CVE-2026-34180",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-06T14:32:24Z",
    "bugzilla": {
      "description": "apr-util: Apache Portable Runtime Utility: SQL Injection via apr_dbd_oracle",
      "id": "2512075",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2512075"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "status": "draft"
    },
    "cwe": "CWE-89",
    "details": [
      "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.\nThis issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3",
      "A flaw was found in Apache Portable Runtime Utility. This vulnerability, known as SQL Injection, occurs in the `apr_dbd_oracle` provider. A remote attacker could exploit this by injecting malicious SQL commands, potentially leading to unauthorized access, modification, or deletion of data within the database."
    ],
    "statement": "Red Hat products are not affected by this flaw. The vulnerability is specific to the apr_dbd_oracle database driver module in the Apache Portable Runtime Utility (apr-util), which provides Oracle database connectivity. Red Hat does not build apr-util with Oracle database support enabled, so the vulnerable code is not present in any shipped Red Hat package.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "apr-util",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34191\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34191\nhttps://lists.apache.org/thread/8xch90zogywwpo5wnsf4o088mkxy4qtf"
    ],
    "name": "CVE-2026-34191",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring type when decoding an op_response packet, causing a server crash when one is encountered in the status vector. An unauthenticated attacker can exploit this by sending a crafted op_response packet to the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34232\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34232"
    ],
    "name": "CVE-2026-34232",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-15T00:00:00Z",
    "bugzilla": {
      "description": "vorbis-tools: vorbis-tools ogg123: Arbitrary code execution via buffer underflow in remote control functionality",
      "id": "2477925",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477925"
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-124",
    "details": [
      "A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.",
      "A flaw was found in the ogg123 utility of the vorbis-tools package. This buffer underflow vulnerability occurs in the remote control functionality when processing malformed input. A remote attacker could exploit this to cause application crashes and potentially achieve arbitrary code execution."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "vorbis-tools",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "vorbis-tools",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "vorbis-tools",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34253\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34253\nhttps://github.com/xiph/vorbis-tools/archive/refs/tags/v1.4.3.tar.gz\nhttps://github.com/xiph/vorbis-tools/blob/0b3fbf42eb3897d32f4a75baa2dc915a4ca45e8e/ogg123/remote.c#L153\nhttps://gitlab.xiph.org/xiph/vorbis-tools/-/work_items/2332"
    ],
    "name": "CVE-2026-34253",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Apr 2026)",
      "id": "2460340",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460340"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "mysql8.4",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "mysql:8.4/mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "mysql:8.4/mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34267\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34267\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-34267",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Group Replication Plugin unspecified vulnerability (CPU Apr 2026)",
      "id": "2460358",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460358"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Under investigation",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34270\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34270\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-34270",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Group Replication Plugin unspecified vulnerability (CPU Apr 2026)",
      "id": "2460276",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460276"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-772",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34271\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34271\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-34271",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Group Replication Plugin unspecified vulnerability (CPU Apr 2026)",
      "id": "2460356",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460356"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34276\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34276\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-34276",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Apr 2026)",
      "id": "2460368",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460368"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "mysql8.4",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "mysql:8.4/mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "mysql:8.4/mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34278\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34278\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-34278",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: DML unspecified vulnerability (CPU Apr 2026)",
      "id": "2460331",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460331"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "mysql8.4",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "mysql:8.4/mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "mysql:8.4/mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34293\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34293\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-34293",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Apr 2026)",
      "id": "2460329",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460329"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34303\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34303\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-34303",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: InnoDB unspecified vulnerability (CPU Apr 2026)",
      "id": "2460344",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460344"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34304\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34304\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-34304",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: JSON unspecified vulnerability (CPU Apr 2026)",
      "id": "2460326",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460326"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34308\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34308\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-34308",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-06T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Shell. CVSS 3.1 Base Score 5.0 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H)."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34317\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34317"
    ],
    "name": "CVE-2026-34317",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-12T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "5.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Shell.  While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Shell accessible data. CVSS 3.1 Base Score 5.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N)."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34318\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34318"
    ],
    "name": "CVE-2026-34318",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-06T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Shell. CVSS 3.1 Base Score 5.0 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H)."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34319\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34319"
    ],
    "name": "CVE-2026-34319",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-08T15:20:30Z",
    "bugzilla": {
      "description": "httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass",
      "id": "2486414",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486414"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.\nUsers are recommended to upgrade to version 2.4.68, which fixes this issue.",
      "A vulnerability has been identified in the Apache HTTP Server. If the server is configured to connect to a malicious or compromised backend server, an attacker could exploit this flaw to bypass security controls or run unauthorized code on the system."
    ],
    "statement": "This Important vulnerability in `mod_proxy_html` within the Apache HTTP Server allows an untrusted backend to trigger a buffer overflow. This could lead to a security bypass or arbitrary code execution, posing a significant risk in environments where `httpd` is configured with untrusted backend services.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34109",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47046",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "httpd-0:2.4.63-1.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42828",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "httpd:2.4-8100020260714175253.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41906",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.5"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25042",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.68-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34355\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34355\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-34355",
    "mitigation": {
      "value": "Disable the `mod_proxy_html` module if it is not essential for your Apache HTTP Server configuration. If `mod_proxy_html` is required, restrict its use to trusted backend servers only, employing network segmentation and access controls. After modifying the configuration, reload the httpd service for changes to apply, which may cause a brief service interruption.\nSteps to disable:\nOpen /etc/httpd/conf.modules.d/00-proxy.conf.\nAdd a # to comment out the line: LoadModule proxy_html_module modules/mod_proxy_html.so\nVerify configuration syntax: apachectl configtest\nApply the change gracefully: systemctl reload httpd",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-08T15:12:21Z",
    "bugzilla": {
      "description": "httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers",
      "id": "2486395",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486395"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
      "A flaw was found in Apache HTTP Server. This heap-based buffer overflow vulnerability can be exploited by a malicious backend server when using ProxyPassReverseCookie* directives. This could lead to a denial of service (DoS) condition, making the server unavailable to legitimate users."
    ],
    "statement": "This flaw in Apache could allow a malicious backend server to crash your web server, making it unavailable to users. Your system is only at risk if you use Apache to forward traffic to untrusted or unverified backend systems.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34109",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47046",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "httpd-0:2.4.63-1.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42828",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "httpd:2.4-8100020260714175253.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41906",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.5"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25042",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.68-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34356\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34356\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-34356",
    "mitigation": {
      "value": "To prevent this denial-of-service flaw, ensure your Apache proxy rules only connect to highly trusted backend servers. If you must proxy traffic to unverified or external backends, disable the cookie-rewriting features.\nSteps to Mitigate:\nOpen your Apache configuration file (e.g., /etc/httpd/conf/httpd.conf).\nLocate and comment out any ProxyPassReverseCookieDomain or ProxyPassReverseCookiePath lines pointing to untrusted backends by adding a # at the start of the line.\nTest your syntax: apachectl configtest\nApply changes gracefully: systemctl reload httpd\nNote: This may cause a brief service interruption.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-27T19:40:28Z",
    "bugzilla": {
      "description": "Varnish Cache: Varnish Cache and Varnish Enterprise: Cache poisoning and authentication bypass via unchecked URL handling",
      "id": "2452408",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452408"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-1286",
    "details": [
      "Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.",
      "A flaw was found in Varnish Cache and Varnish Enterprise. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/1.1 requests with a path of `/` in the URL. This mishandling of URLs, specifically in unchecked `req.url` scenarios, could lead to cache poisoning, where an attacker manipulates cached content, or an authentication bypass, allowing unauthorized access."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/varnish-7-10-0",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/varnish-7-10-1",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "varnish",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "varnish-modules",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/varnish-6-8-10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "varnish:6/varnish",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "varnish:6/varnish-modules",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/varnish-6-9-6",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "redhat-user-workloads/varnish-6-9-7",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "varnish",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "varnish-modules",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34475\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34475\nhttps://vinyl-cache.org/security/VSV00018.html"
    ],
    "name": "CVE-2026-34475",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-06T14:31:48Z",
    "bugzilla": {
      "description": "apr-util: Apache Portable Runtime Utility: Heap buffer overflow in redis client",
      "id": "2512073",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2512073"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.\nThis issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3.\nUsers are recommended to upgrade to version 1.6.4, which fixes the issue.",
      "A flaw was found in the Redis client in the Apache Portable Runtime Utility (apr-util). A heap buffer overflow can be triggered when the application processes a specially crafted response from a Redis server, resulting in a crash and denial of service."
    ],
    "statement": "The impact of this vulnerability is rated as Moderate. Although the flaw involves a heap buffer overflow and the CVSS base score reflects an unauthenticated network vector, exploitation requires the attacker to control or compromise the Redis server that the application queries. An attacker cannot trigger this condition by sending data directly to the affected application — they must first be in a position to influence Redis responses, either by compromising the Redis backend or performing a man-in-the-middle attack on the connection. Additionally, the overflow does not result in arbitrary code execution; the observed impact is limited to a denial of service. This prerequisite significantly limits real-world exploitability.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-22T00:00:00Z",
        "advisory": "RHSA-2026:58474",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "apr-util-main-1.6.5-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34501\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34501\nhttps://lists.apache.org/thread/o8h6c7cq86fplxlnry6c3rn9x0ovq8mv"
    ],
    "name": "CVE-2026-34501",
    "mitigation": {
      "value": "Ensure that the Redis server used by the application is deployed in a trusted, network-segregated environment and is not accessible to untrusted parties. Where possible, configure authentication and TLS on the Redis connection to reduce the risk of a compromised or spoofed Redis server.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-06T14:31:07Z",
    "bugzilla": {
      "description": "apr-util: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client",
      "id": "2512083",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2512083"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client\nThis issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.",
      "A flaw was found in the memcached client in the Apache Portable Runtime Utility (apr-util). A remote, unauthenticated attacker can cause the application to crash or become unresponsive by sending a specially crafted response from a malicious or compromised memcached server, resulting in a denial of service."
    ],
    "statement": "The impact of this vulnerability is rated as Moderate. While the flaw is network-reachable and requires no authentication against the application itself, exploitation depends on the attacker controlling or compromising the memcached server that the application queries. An attacker cannot trigger the denial of service by sending data directly to the affected application — they must first be in a position to influence memcached responses, either by compromising the memcached backend or performing a man-in-the-middle attack on the connection between the application and memcached. This prerequisite significantly limits the real-world exploitability compared to a direct network denial-of-service attack.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-22T00:00:00Z",
        "advisory": "RHSA-2026:58474",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "apr-util-main-1.6.5-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "apr-util",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34502\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34502\nhttps://lists.apache.org/thread/spk5643m4vq0mb8h5b9hz9gkp57ombl8"
    ],
    "name": "CVE-2026-34502",
    "mitigation": {
      "value": "Restrict network access for applications that use the `apr-util` memcached client to communicate only with trusted memcached servers. Ensure that Red Hat products are configured to avoid connecting to untrusted or publicly exposed memcached instances. If the memcached client functionality is not essential, consider disabling or removing any dependent components. A service restart may be required for changes to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-09T14:41:18Z",
    "bugzilla": {
      "description": "libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability",
      "id": "2456918",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456918"
    },
    "cvss3": {
      "cvss3_base_score": "4.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_struct/png_info pair causes the setter to read from freed memory and copy its contents into the replacement buffer. The setter frees the internal buffer before copying from the caller-supplied pointer, which now dangles. The freed region may contain stale data (producing silently corrupted chunk metadata) or data from subsequent heap allocations (leaking unrelated heap contents into the chunk struct). This vulnerability is fixed in 1.6.57.",
      "A flaw was found in libpng, a library used for handling PNG (Portable Network Graphics) image files. This vulnerability arises when an application reuses a pointer, previously obtained from functions like png_get_PLTE, by passing it back to a corresponding setter function within the same image structure. This action causes the setter to access memory that has already been deallocated, leading to a use-after-free condition. A local attacker could potentially exploit this flaw to corrupt image metadata or disclose sensitive information from the application's memory."
    ],
    "statement": "There's a use-after-free vulnerability in libpng. The flaw occurs when an application reuses a pointer from `png_get_PLTE`, `png_get_tRNS`, or `png_get_hIST` and passes it to a corresponding setter, leading to memory corruption or information disclosure. A local attacker could exploit this if a vulnerable application processes PNG files in this specific manner.\nRed Hat Product Security team has rated this as having a moderate impact as the user needs to be tricked to open the maliciously crafted PNG image, additionally the attacker doesn't have full control if the content it's exfiltrating or corruption in the memory.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13719",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libpng-main-1.6.57-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Fix deferred",
        "package_name": "java-11-openjdk",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Fix deferred",
        "package_name": "java-11-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Fix deferred",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Fix deferred",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Fix deferred",
        "package_name": "java-21-openjdk-vanilla",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 11 ELS",
        "fix_state": "Fix deferred",
        "package_name": "java-25-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk_els:11"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Fix deferred",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Fix deferred",
        "package_name": "java-17-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Fix deferred",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Fix deferred",
        "package_name": "java-21-openjdk-vanilla",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 17",
        "fix_state": "Fix deferred",
        "package_name": "java-25-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:17"
      },
      {
        "product_name": "Red Hat build of OpenJDK 1.8",
        "fix_state": "Fix deferred",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:1.8"
      },
      {
        "product_name": "Red Hat build of OpenJDK 1.8",
        "fix_state": "Fix deferred",
        "package_name": "java-1.8.0-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:1.8"
      },
      {
        "product_name": "Red Hat build of OpenJDK 1.8",
        "fix_state": "Fix deferred",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:1.8"
      },
      {
        "product_name": "Red Hat build of OpenJDK 1.8",
        "fix_state": "Fix deferred",
        "package_name": "java-21-openjdk-vanilla",
        "cpe": "cpe:/a:redhat:openjdk:1.8"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Fix deferred",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Fix deferred",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Fix deferred",
        "package_name": "java-21-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Fix deferred",
        "package_name": "java-21-openjdk-vanilla",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 21",
        "fix_state": "Fix deferred",
        "package_name": "java-25-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:21"
      },
      {
        "product_name": "Red Hat build of OpenJDK 25",
        "fix_state": "Fix deferred",
        "package_name": "java-25-openjdk-portable",
        "cpe": "cpe:/a:redhat:openjdk:25"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "java-25-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libpng",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "libpng",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libpng",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libpng12",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "java-1.8.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libpng",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libpng12",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libpng15",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-libpng",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "java-17-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "java-1.8.0-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "java-21-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "java-25-openjdk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libpng",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libpng15",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34757\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34757\nhttps://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a\nhttps://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc\nhttps://github.com/pnggroup/libpng/issues/836\nhttps://github.com/pnggroup/libpng/issues/837\nhttps://github.com/pnggroup/libpng/security/advisories/GHSA-6fr7-g8h7-v645"
    ],
    "name": "CVE-2026-34757",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-31T00:00:00Z",
    "bugzilla": {
      "description": "openvswitch: Open vSwitch: Denial of Service via malformed FTP EPASV command",
      "id": "2453459",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453459"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-120",
    "details": [
      "A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.",
      "A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system."
    ],
    "statement": "This vulnerability in Open vSwitch, leading to a heap access error and potential denial of service, is not exploitable in default Red Hat configurations. Exploitation requires Open vSwitch to be specifically configured with FTP helpers over the userspace datapath, which is not enabled by default.",
    "acknowledgement": "Red Hat would like to thank Seiji Sakurai for reporting this issue.",
    "package_state": [
      {
        "product_name": "Fast Datapath for RHEL 7",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch",
        "cpe": "cpe:/o:redhat:enterprise_linux:7::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 7",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch2.10",
        "cpe": "cpe:/o:redhat:enterprise_linux:7::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 7",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch2.11",
        "cpe": "cpe:/o:redhat:enterprise_linux:7::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 7",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch2.12",
        "cpe": "cpe:/o:redhat:enterprise_linux:7::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 7",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch2.13",
        "cpe": "cpe:/o:redhat:enterprise_linux:7::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 7",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch-selinux-extra-policy",
        "cpe": "cpe:/o:redhat:enterprise_linux:7::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 7",
        "fix_state": "Fix deferred",
        "package_name": "ovn2.11",
        "cpe": "cpe:/o:redhat:enterprise_linux:7::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 7",
        "fix_state": "Fix deferred",
        "package_name": "ovn2.12",
        "cpe": "cpe:/o:redhat:enterprise_linux:7::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 8",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch2.11",
        "cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 8",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch2.12",
        "cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 8",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch2.13",
        "cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 8",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch2.15",
        "cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 8",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch2.16",
        "cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 8",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch2.17",
        "cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 8",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch3.1",
        "cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 8",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch-selinux-extra-policy",
        "cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 8",
        "fix_state": "Fix deferred",
        "package_name": "ovn2.11",
        "cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 8",
        "fix_state": "Fix deferred",
        "package_name": "ovn2.12",
        "cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 9",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch2.17",
        "cpe": "cpe:/o:redhat:enterprise_linux:9::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 9",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch3.0",
        "cpe": "cpe:/o:redhat:enterprise_linux:9::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 9",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch3.1",
        "cpe": "cpe:/o:redhat:enterprise_linux:9::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 9",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch3.2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 9",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch3.3",
        "cpe": "cpe:/o:redhat:enterprise_linux:9::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 9",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch3.4",
        "cpe": "cpe:/o:redhat:enterprise_linux:9::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 9",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch3.5",
        "cpe": "cpe:/o:redhat:enterprise_linux:9::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 9",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch3.6",
        "cpe": "cpe:/o:redhat:enterprise_linux:9::fastdatapath"
      },
      {
        "product_name": "Fast Datapath for RHEL 9",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch-selinux-extra-policy",
        "cpe": "cpe:/o:redhat:enterprise_linux:9::fastdatapath"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch2.17",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch3.0",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openvswitch3.1",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 13 (Queens)",
        "fix_state": "Fix deferred",
        "package_name": "rhosp13/openstack-neutron-openvswitch-agent",
        "cpe": "cpe:/a:redhat:openstack:13"
      },
      {
        "product_name": "Red Hat OpenStack Platform 13 (Queens)",
        "fix_state": "Fix deferred",
        "package_name": "rhosp13/openstack-openvswitch-base",
        "cpe": "cpe:/a:redhat:openstack:13"
      },
      {
        "product_name": "Red Hat OpenStack Platform 13 (Queens)",
        "fix_state": "Fix deferred",
        "package_name": "rhosp13/openstack-ovn-base",
        "cpe": "cpe:/a:redhat:openstack:13"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-openvswitch",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel8/openstack-neutron-openvswitch-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-openvswitch",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "rhosp-rhel9/openstack-neutron-openvswitch-agent",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso-openvswitch",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34956\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34956"
    ],
    "name": "CVE-2026-34956",
    "mitigation": {
      "value": "Optionally, avoid using alg=ftp flows. These are not usually configured.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-12T18:27:44Z",
    "bugzilla": {
      "description": "openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables",
      "id": "2447085",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447085"
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-824",
    "details": [
      "Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.",
      "A flaw was found in the OpenSSH GSSAPI (Generic Security Service Application Program Interface) delta patches, as included in various Linux distributions. A remote attacker could exploit this by sending an unexpected GSSAPI message type during the key exchange process. This occurs because the `sshpkt_disconnect()` function, when called on an error, does not properly terminate the process, leading to the continued execution of the program with uninitialized connection variables. Accessing these uninitialized variables can lead to undefined behavior, potentially resulting in information disclosure or a denial of service."
    ],
    "statement": "IMPORTANT: This vulnerability affects the OpenSSH GSSAPI delta as implemented in Red Hat Enterprise Linux and OpenShift Container Platform. An unauthenticated attacker could send a specially crafted GSSAPI message during key exchange, leading to the use of uninitialized variables and potentially undefined behavior. The severity of the impact is dependent on compiler hardening configurations.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6463",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssh-0:9.9p1-13.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7107",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "openssh-0:9.9p1-7.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6461",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "openssh-0:8.0p1-28.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6461",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "openssh-0:8.0p1-28.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15891",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "openssh-0:8.0p1-7.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15891",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "openssh-0:8.0p1-7.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15893",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15893",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15893",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14924",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "openssh-0:8.0p1-20.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14924",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "openssh-0:8.0p1-20.el8_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6462",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssh-0:8.7p1-48.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-02T00:00:00Z",
        "advisory": "RHSA-2026:6462",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssh-0:8.7p1-48.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13750",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "openssh-0:8.7p1-13.el9_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10714",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "openssh-0:8.7p1-30.el9_2.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9732",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "openssh-0:8.7p1-38.el9_4.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9415",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "openssh-0:8.7p1-45.el9_6.2"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21695",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202605271418-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21690",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202605271328-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:15087",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202605060243-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14773",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202605060220-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20087",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202605200242-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17596",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202605112123-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:12071",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202604240015-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20040",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202605201155-0"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1777325677"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1777325711"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-controller-rhel8:7.13.5-4.1777325710"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1777325680"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1777325709"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1777325680"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1777325708"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19724",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1779223654"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19725",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1779223651"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16008",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1778244559"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16009",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1778244531"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16030",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1778274666"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-03-23T00:00:00Z",
        "advisory": "RHSA-2026:5475",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssh-main-10.2p1-9.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1776868772"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      }
    ],
    "package_state": [
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Under investigation",
        "package_name": "multicluster-engine/hive-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Under investigation",
        "package_name": "openshift-pipelines/pipelines-resolvers-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Under investigation",
        "package_name": "rhacm2/multicluster-operators-subscription-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-3497\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-3497\nhttps://ubuntu.com/security/CVE-2026-3497\nhttps://www.openwall.com/lists/oss-security/2026/03/12/3"
    ],
    "name": "CVE-2026-3497",
    "mitigation": {
      "value": "To mitigate this issue, disable GSSAPI key exchange in the OpenSSH server configuration. This prevents the server from processing GSSAPI messages, eliminating the vulnerability's attack surface.\nEdit `/etc/ssh/sshd_config` and add or modify the line:\n```\nGSSAPIKeyExchange no\n```\nAfter saving the changes, restart the `sshd` service for the mitigation to take effect. This action will prevent users from authenticating via GSSAPI.\n```\n# systemctl restart sshd\n```",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-03T21:15:15Z",
    "bugzilla": {
      "description": "cups: OpenPrinting CUPS: Denial of Service via path traversal in RSS notifier",
      "id": "2454957",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454957"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-22",
    "details": [
      "OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.",
      "A flaw was found in OpenPrinting CUPS. A remote attacker can exploit a path traversal vulnerability in the RSS notifier by manipulating the `notify-recipient-uri`. This allows writing arbitrary RSS XML data to sensitive files outside the intended directory. This can lead to a denial of service (DoS) by corrupting critical system files, such as the job cache, causing the scheduler to fail and previously queued jobs to disappear."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8814",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "cups-main-2.4.17-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34978\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34978\nhttps://github.com/OpenPrinting/cups/security/advisories/GHSA-f53q-7mxp-9gcr"
    ],
    "name": "CVE-2026-34978",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-03T21:16:38Z",
    "bugzilla": {
      "description": "cups: OpenPrinting CUPS: Denial of Service via heap-based buffer overflow in job attribute processing",
      "id": "2454946",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454946"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-based buffer overflow in the CUPS scheduler when building filter option strings from job attribute. At time of publication, there are no publicly available patches.",
      "A flaw was found in OpenPrinting CUPS. A remote attacker could exploit a heap-based buffer overflow by sending specially crafted job attributes when building filter option strings. This could lead to a denial of service, making the printing system unavailable."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8814",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "cups-main-2.4.17-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34979\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34979\nhttps://github.com/OpenPrinting/cups/security/advisories/GHSA-6qxf-7jx6-86fh"
    ],
    "name": "CVE-2026-34979",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-03T21:18:09Z",
    "bugzilla": {
      "description": "cups: OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network",
      "id": "2454954",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454954"
    },
    "cvss3": {
      "cvss3_base_score": "6.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-78",
    "details": [
      "OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches.",
      "A flaw was found in OpenPrinting CUPS. An unauthorized client can exploit this vulnerability by sending a specially crafted print job to a shared PostScript queue without authentication. The server improperly handles the `page-border` value, allowing an attacker to embed and reparse malicious text as a trusted scheduler control record. This can lead to arbitrary code execution with the privileges of the 'lp' user, potentially compromising the affected system."
    ],
    "statement": "This issue is classified as moderate severity primarily because: \n* Affected Component: The vulnerability specifically affects the core cups daemon package (which handles the print scheduler and target queues) and does not affect the utility libraries (cups-libs).\n* Conditions for Exploitation: Exploitation requires a network-exposed CUPS daemon (cupsd) configured with an active, shared PostScript target queue. A remote, unauthenticated attacker must be able to reach this daemon over the network and submit a crafted print job to the shared queue.\n* Impact Limitations: While the flaw allows for remote command execution, the execution is strictly limited to utilizing existing binaries already present on the system. Furthermore, these commands run under the restricted privileges of the unprivileged service user (lp) rather than the root or administrative user, preventing direct, full system compromise.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39302",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "cups-1:2.4.10-18.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36733",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "cups-1:2.2.6-68.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36733",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "cups-1:2.2.6-68.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39316",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "cups-1:2.3.3op2-39.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39316",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "cups-1:2.3.3op2-39.el9_8"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8814",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "cups-main-2.4.17-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34980\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34980\nhttps://github.com/OpenPrinting/cups/security/advisories/GHSA-4852-v58g-6cwf"
    ],
    "name": "CVE-2026-34980",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-06T15:16:48Z",
    "bugzilla": {
      "description": "vim: arbitrary command execution via modeline sandbox bypass",
      "id": "2455400",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455400"
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-78",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.",
      "A flaw was found in Vim. A modeline is used to set specific editor options directly from a text file. However, the `complete`, `guitabtooltip`, `printheader` options and the `mapset` function lack proper security checks, allowing an attacker to bypass restrictions and cause arbitrary OS command execution."
    ],
    "statement": "To exploit this vulnerability, an attacker needs to convince a user to open a specially crafted file. The arbitrary OS command execution is restricted to the privileges of the user running Vim, limiting the potential of a full system compromise.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11389",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "vim-2:9.1.083-6.el10_1.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19073",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "vim-2:9.1.083-9.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30900",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11509",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-22.el8_10.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11509",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-22.el8_10.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33453",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33453",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34477",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34477",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34476",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34476",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11510",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-23.el9_7.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19224",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11510",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-23.el9_7.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19224",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28133",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "vim-2:8.2.2637-20.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:28049",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "vim-2:8.2.2637-20.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:28050",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "vim-2:8.2.2637-22.el9_6.3"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36004",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1782951051"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36005",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1782951012"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36006",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782951244"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30078",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1782352950"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30087",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1782352919"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30088",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782353093"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30089",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1782352847"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22634",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1780420428"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1779798159"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1779798164"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34982\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34982\nhttp://www.openwall.com/lists/oss-security/2026/04/01/1\nhttps://github.com/vim/vim/commit/75661a66a1db1e1f3f1245c615\nhttps://github.com/vim/vim/releases/tag/v9.2.0276\nhttps://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9"
    ],
    "name": "CVE-2026-34982",
    "mitigation": {
      "value": "To mitigate this issue, disable the modeline support by adding the following command to the Vim configuration file:\n~~~\nset nomodeline\n~~~",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-06T16:22:45Z",
    "bugzilla": {
      "description": "github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object",
      "id": "2455470",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455470"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reachable by calling cipher.KeyUnwrap() directly with any ciphertext parameter less than 16 bytes long, but calling this function directly is less common. Panics can lead to denial of service. This vulnerability is fixed in 4.1.4 and 3.0.5.",
      "A flaw was found in Go JOSE, a library for handling JSON Web Encryption (JWE) objects. A remote attacker could exploit this vulnerability by providing a specially crafted JWE object. When decrypting such an object, if a key wrapping algorithm is specified but the encrypted key field is empty, the application can crash. This leads to a denial of service (DoS), making the affected service unavailable to legitimate users."
    ],
    "affected_release": [
      {
        "product_name": "Cryostat 4 on RHEL 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:17789",
        "cpe": "cpe:/a:redhat:cryostat:4::el9",
        "package": "cryostat/cryostat-storage-rhel9:4.2.0-13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19017",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "podman-7:5.8.2-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19135",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "opentelemetry-collector-0:0.144.0-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22450",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "osbuild-composer-0:165.1-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22937",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "image-builder-0:52.1-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57590",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "rh-podman-desktop-0:1.1.2-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16696",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "skopeo-2:1.18.1-3.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17040",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "podman-6:5.4.0-15.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19719",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "opentelemetry-collector-0:0.144.0-2.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20569",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "buildah-2:1.39.9-1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27856",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "osbuild-composer-0:134.1-9.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33722",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "container-tools:rhel8-8100020260520103055.afee755d"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35833",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "container-tools:rhel8-8100020260701102925.afee755d"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48790",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "osbuild-composer-0:101.5-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49944",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "container-tools:rhel8-8080020260721142025.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49944",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "container-tools:rhel8-8080020260721142025.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-24T00:00:00Z",
        "advisory": "RHSA-2026:10135",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "buildah-2:1.41.8-3.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19173",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "podman-6:5.8.2-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19186",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "buildah-2:1.43.1-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19353",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "opentelemetry-collector-0:0.144.0-2.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22714",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "osbuild-composer-0:165.1-2.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23228",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "image-builder-0:52.1-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25248",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "podman-2:4.4.1-22.el9_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25250",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "skopeo-2:1.11.4-0.1.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25252",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "buildah-1:1.29.7-1.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19721",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "opentelemetry-collector-0:0.144.0-2.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32991",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "osbuild-composer-0:101.3-4.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34192",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "buildah-2:1.33.15-1.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34196",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "podman-4:4.9.4-20.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34197",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "skopeo-2:1.14.6-1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17287",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "podman-5:5.4.0-20.el9_6.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19720",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "opentelemetry-collector-0:0.144.0-2.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20607",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "buildah-2:1.39.9-1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20609",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "skopeo-2:1.18.1-5.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:26054",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "osbuild-composer-0:132.2-8.el9_6"
      },
      {
        "product_name": "Custom Metric Autoscaler 2.19",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26636",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2.19::el9",
        "package": "custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9:1780101236"
      },
      {
        "product_name": "Custom Metric Autoscaler 2.19",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26636",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2.19::el9",
        "package": "custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9:1780101226"
      },
      {
        "product_name": "Custom Metric Autoscaler 2.19",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26636",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2.19::el9",
        "package": "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9:1780101239"
      },
      {
        "product_name": "Custom Metric Autoscaler 2.19",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26636",
        "cpe": "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2.19::el9",
        "package": "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator:1779953535"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.0",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26585",
        "cpe": "cpe:/a:redhat:logging:6.0::el9",
        "package": "openshift-logging/lokistack-gateway-rhel9:1781192909"
      },
      {
        "product_name": "Logging for Red Hat OpenShift 6.2",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47952",
        "cpe": "cpe:/a:redhat:logging:6.2::el9",
        "package": "openshift-logging/lokistack-gateway-rhel9:1784747816"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift 6.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34364",
        "cpe": "cpe:/a:redhat:logging:6.4::el9",
        "package": "openshift-logging/cluster-logging-rhel9-operator:1782412815"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift 6.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34364",
        "cpe": "cpe:/a:redhat:logging:6.4::el9",
        "package": "openshift-logging/lokistack-gateway-rhel9:1782392961"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12116",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/assisted-installer-agent-rhel9:1776351169"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19099",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/assisted-service-9-rhel9:1779135478"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46885",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/must-gather-rhel9:1784849867"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47388",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/must-gather-rhel9:1784849867"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.11.0",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19108",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.11::el9",
        "package": "multicluster-engine/assisted-service-9-rhel9:1778892370"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17459",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el8",
        "package": "multicluster-engine/assisted-installer-controller-rhel8:1778507267"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17459",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el8",
        "package": "multicluster-engine/assisted-installer-rhel8:1778507253"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17459",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el8",
        "package": "multicluster-engine/assisted-service-8-rhel8:1778476004"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28198",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el8",
        "package": "multicluster-engine/assisted-installer-agent-rhel8:1782203505"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28198",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el8",
        "package": "multicluster-engine/assisted-installer-controller-rhel8:1782204403"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28198",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el8",
        "package": "multicluster-engine/assisted-installer-rhel8:1782204381"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17458",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el9",
        "package": "multicluster-engine/assisted-service-9-rhel9:1778476002"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.7",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11512",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.7::el9",
        "package": "multicluster-engine/assisted-installer-agent-rhel9:1777360597"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17121",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el8",
        "package": "multicluster-engine/assisted-service-8-rhel8:1778288655"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22258",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el8",
        "package": "multicluster-engine/assisted-service-8-rhel8:1779910504"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17123",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/assisted-installer-agent-rhel9:1778503377"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17123",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/assisted-installer-controller-rhel9:1778503196"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17123",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/assisted-installer-rhel9:1778503297"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17123",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/assisted-service-9-rhel9:1778288646"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22260",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/assisted-service-9-rhel9:1779910129"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-06-28T00:00:00Z",
        "advisory": "RHSA-2026:30650",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/must-gather-rhel9:1782158798"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18584",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.9::el8",
        "package": "multicluster-engine/assisted-service-8-rhel8:1778464111"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:18585",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.9::el9",
        "package": "multicluster-engine/assisted-service-9-rhel9:1778464072"
      },
      {
        "product_name": "Multicluster Global Hub 1.3.4",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22423",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.3::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21769",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-mustgather-rhel9:1785177359"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29854",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-mustgather-rhel9:1779770049"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.4",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29854",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.4::el9",
        "package": "oadp/oadp-velero-plugin-rhel9:1779243793"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26568",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-mustgather-rhel9:1779770057"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.5",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26568",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.5::el9",
        "package": "oadp/oadp-velero-plugin-rhel9:1779245274"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25127",
        "cpe": "cpe:/a:redhat:acm:2.14::el9",
        "package": "rhacm2/submariner-rhel9-operator:1780204322"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11070",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1777307791"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11070",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-roxctl-rhel8:1777307791"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11070",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-scanner-rhel8:1776727747"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11070",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-scanner-slim-rhel8:1776727747"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11070",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-scanner-v4-rhel8:1777307791"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11217",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1777307791"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11217",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-roxctl-rhel8:1777307791"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11217",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-scanner-rhel8:1776727747"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11217",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-scanner-slim-rhel8:1776727747"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11217",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-scanner-v4-rhel8:1777307791"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.10",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13829",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.10::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1777976489"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13791",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1777986630"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13791",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-roxctl-rhel8:1777986630"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13791",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-scanner-v4-rhel8:1777986630"
      },
      {
        "product_name": "Red Hat Migration Toolkit 1.8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41928",
        "cpe": "cpe:/a:redhat:rhmt:1.8::el8",
        "package": "rhmtc/openshift-migration-controller-rhel8:1783953372"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22347",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23345",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24977",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-model-controller-rhel9:1780069381"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-kube-auth-proxy-rhel9:1778696221"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19712",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-model-controller-rhel9:1778578758"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-telemeter-rhel9:1778711679"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34099",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1782185551"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17448",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-telemeter-rhel9:1778152595"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:27001",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1781612340"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-telemeter-rhel9:1779253452"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:27004",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1781528081"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17468",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-telemeter-rhel9:1778139790"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21703",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cli-rhel9:1779775173"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21703",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1779776767"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21703",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1779777382"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21703",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1779778558"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21703",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1779775521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21703",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1779776141"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:25194",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1780992173"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:25194",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1780991067"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:25194",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1781095245"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:27063",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1781196942"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:48676",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1785288355"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:17474",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-telemeter-rhel9:1778004922"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20034",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-machine-config-rhel9-operator:1779258037"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20034",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-olm-catalogd-rhel9:1779264135"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20034",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-olm-operator-controller-rhel9:1779263963"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20034",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-operator-framework-tools-rhel9:1779256521"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20034",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-operator-lifecycle-manager-rhel9:1779260263"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20034",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-operator-registry-rhel9:1779265022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:21709",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-cli-rhel9:1779775977"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:23241",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-cloud-credential-rhel9-operator:1780402732"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:23241",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-kube-state-metrics-rhel9:1780402633"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:25187",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/oc-mirror-plugin-rhel9:1780984236"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:25187",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1781023907"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:27044",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1781129269"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:44267",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-azure-workload-identity-webhook-rhel9:1784343578"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54602",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1786572999"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:25206",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "openshift4/ose-installer-artifacts-rhel9:1781010151"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:25206",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "openshift4/ose-oauth-server-rhel9:1780943933"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:34794",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "openshift4/ose-agent-installer-node-agent-rhel9:1782879990"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/cephcsi-rhel9:1778049594"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/cephcsi-rhel9-operator:1778049298"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/mcg-core-rhel9:1778049745"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/mcg-rhel9-operator:1778049753"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/ocs-client-console-rhel9:1778050558"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/ocs-client-rhel9-operator:1778049818"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1778049878"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/ocs-rhel9-operator:1778049920"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/odf-cli-rhel9:1778049945"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/odf-console-rhel9:1778060364"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1778050037"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1778050035"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1778050048"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1778050508"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1778050119"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/odf-must-gather-rhel9:1778050290"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/odf-rhel9-operator:1778059723"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/odr-rhel9-operator:1778050352"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17550",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1778050482"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9:1778045210"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9-operator:1778044961"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-core-rhel9:1778045359"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-rhel9-operator:1778045374"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-console-rhel9:1778045891"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-rhel9-operator:1778045472"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1778045534"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-rhel9-operator:1778045524"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cli-rhel9:1778045587"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-console-rhel9:1778046067"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1778045627"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1778045731"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1778045700"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1778046234"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1778045792"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-must-gather-rhel9:1778045858"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-rhel9-operator:1778045945"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odr-rhel9-operator:1778045931"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17547",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1778046079"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9:1783676191"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9-operator:1783929816"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-core-rhel9:1784094353"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-rhel9-operator:1784093953"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-console-rhel9:1784094943"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-rhel9-operator:1783676585"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1783676649"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-rhel9-operator:1783676675"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cli-rhel9:1784094299"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-console-rhel9:1784094725"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1783676820"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1783676883"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1783676894"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1784095175"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1783676977"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-must-gather-rhel9:1784093503"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-rhel9-operator:1783677297"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odr-rhel9-operator:1783677345"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41941",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1783677533"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9:1786705347"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9-operator:1786706101"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-core-rhel9:1786705558"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-rhel9-operator:1786705646"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-console-rhel9:1786706138"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-rhel9-operator:1786705741"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1786705777"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-rhel9-operator:1786705802"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cli-rhel9:1786705938"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-console-rhel9:1786706577"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1786706125"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1786706177"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1786706188"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1786706679"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1786706357"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-must-gather-rhel9:1786706612"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-rhel9-operator:1786706644"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odr-rhel9-operator:1786706659"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1786706880"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9:1776079019"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9-operator:1776706744"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-core-rhel9:1776707205"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-rhel9-operator:1776707231"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-console-rhel9:1776707760"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-rhel9-operator:1776707301"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1776079295"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-rhel9-operator:1776707362"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cli-rhel9:1776707418"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1776707377"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-console-rhel9:1776707947"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1776707456"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1776707526"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1776707526"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1776707945"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1776707569"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-must-gather-rhel9:1776707724"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-rhel9-operator:1776707763"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odr-rhel9-operator:1776707771"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12279",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1776079774"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9:1783684360"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9-operator:1783684068"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-core-rhel9:1784054582"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-rhel9-operator:1784054606"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-console-rhel9:1784055295"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-rhel9-operator:1783684603"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1783684668"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-rhel9-operator:1783684667"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cli-rhel9:1784054873"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1783684707"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-console-rhel9:1784055589"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1783684779"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1783684831"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1783684839"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1784055533"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1784055558"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-must-gather-rhel9:1784056134"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-rhel9-operator:1783685128"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odr-rhel9-operator:1783685129"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41944",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1783685375"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9:1786701839"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9-operator:1786701555"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-core-rhel9:1786702052"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-rhel9-operator:1786702559"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-console-rhel9:1786702713"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-rhel9-operator:1786702264"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1786702448"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-rhel9-operator:1786702276"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cli-rhel9:1786702440"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1786702315"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-console-rhel9:1786703071"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1786702563"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1786702636"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1786702623"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1786703137"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1786702716"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-must-gather-rhel9:1786702872"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-rhel9-operator:1786702949"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odr-rhel9-operator:1786702917"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1786703143"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/cephcsi-rhel9:1775822432"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/cephcsi-rhel9-operator:1776403457"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/mcg-core-rhel9:1776403991"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/mcg-rhel9-operator:1776404009"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-client-console-rhel9:1776404539"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-client-rhel9-operator:1776404060"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1775822689"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-rhel9-operator:1776404131"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cli-rhel9:1776406225"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1776406131"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-console-rhel9:1776406770"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1776406247"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1776406286"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1776406291"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-external-snapshotter-rhel9-operator:1776406284"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-external-snapshotter-sidecar-rhel9:1776406291"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1776406771"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1776406384"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-must-gather-rhel9:1776406540"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-rhel9-operator:1776406595"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odr-rhel9-operator:1776406594"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12277",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1775823207"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/cephcsi-rhel9:1783667125"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/cephcsi-rhel9-operator:1783666755"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/mcg-core-rhel9:1784054598"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/mcg-rhel9-operator:1784055387"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-client-console-rhel9:1784055726"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-client-rhel9-operator:1783667517"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1783667577"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-rhel9-operator:1783667611"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cli-rhel9:1784055020"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1783667641"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-console-rhel9:1784055586"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1783667790"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1783667859"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1783667875"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-external-snapshotter-rhel9-operator:1783667869"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-external-snapshotter-sidecar-rhel9:1783667877"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1784055576"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1784055244"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-must-gather-rhel9:1784055382"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-rhel9-operator:1783668266"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odr-rhel9-operator:1783668288"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40984",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1783669219"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/cephcsi-rhel9:1786627460"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/cephcsi-rhel9-operator:1786626399"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/mcg-core-rhel9:1786628235"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/mcg-rhel9-operator:1786627106"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-client-console-rhel9:1786629761"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-client-rhel9-operator:1786627559"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1786687918"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-rhel9-operator:1786629478"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cli-rhel9:1786628142"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1786631508"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-console-rhel9:1786628053"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1786627382"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1786627430"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1786629076"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-external-snapshotter-rhel9-operator:1786627469"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-external-snapshotter-sidecar-rhel9:1786644072"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1786688215"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1786628340"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-must-gather-rhel9:1786628623"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-rhel9-operator:1786632256"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odr-rhel9-operator:1786628935"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1786629548"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/cephcsi-rhel9:1786627281"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/cephcsi-rhel9-operator:1786627168"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/devicefinder-rhel9:1786628067"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/mcg-core-rhel9:1786628657"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/mcg-rhel9-operator:1786627792"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/ocs-client-console-rhel9:1786698066"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/ocs-client-rhel9-operator:1786627823"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1786628998"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/ocs-rhel9-operator:1786697443"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-blackbox-exporter-rhel9:1786628916"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-cli-rhel9:1786630412"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1786629773"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-console-rhel9:1786630739"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1786628303"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1786629324"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1786628605"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-external-snapshotter-rhel9-operator:1786631438"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-external-snapshotter-sidecar-rhel9:1786697305"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-lightspeed-rag-content-rhel9:1786644678"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1786634168"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1786633448"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-must-gather-rhel9:1786634233"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-rhel9-operator:1786633986"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odr-rhel9-operator:1786633677"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56968",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1786644362"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/cephcsi-rhel9:1782932114"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/cephcsi-rhel9-operator:1782931768"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/devicefinder-rhel9:1782932104"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/mcg-core-rhel9:1783536000"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/mcg-rhel9-operator:1783535989"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-client-console-rhel9:1783536515"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-client-rhel9-operator:1782932521"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1783018461"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-rhel9-operator:1783018421"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-blackbox-exporter-rhel9:1782932812"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cli-rhel9:1783537001"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1782932919"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-console-rhel9:1783537586"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1782932969"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1782933015"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1782933042"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-drbd-rhel9:1783537392"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-external-snapshotter-rhel9-operator:1782933235"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-external-snapshotter-sidecar-rhel9:1782933251"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1783537955"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1782933417"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-must-gather-rhel9:1783537742"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-rhel9-operator:1782933602"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-rhel9-operator:1783019377"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-volsync-plugin-mover-rhel9:1782934054"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-volsync-plugin-rhel9-operator:1782934036"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1782934284"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.27",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10175",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.27::el9",
        "package": "devspaces/traefik-rhel9:1776718585"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.29",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36820",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.29::el9",
        "package": "devspaces/udi-base-rhel10:1782987430"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9385",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/tempo-gateway-rhel9:1776435643"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9385",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/tempo-query-rhel9:1776435613"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9385",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/tempo-rhel9:1776435680"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9388",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/opentelemetry-collector-rhel9:1776185379"
      },
      {
        "product_name": "Red Hat OpenShift GitOps 1.18",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20946",
        "cpe": "cpe:/a:redhat:openshift_gitops:1.18::el8",
        "package": "openshift-gitops-1/dex-rhel8:1779116359"
      },
      {
        "product_name": "Red Hat OpenShift Pipelines 1.2",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:21931",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1.20::el9",
        "package": "openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9:1779865001"
      },
      {
        "product_name": "Red Hat OpenShift Pipelines 1.2",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:21932",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1.20::el9",
        "package": "openshift-pipelines/pipelines-operator-bundle:1780044955"
      },
      {
        "product_name": "Red Hat OpenShift Pipelines 1.21",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24484",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1.21::el9",
        "package": "serve-tkn-cli-1-21-serve-tkn-cli-1.21.1"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11688",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/istio-cni-rhel8:1777374598"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11688",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el8",
        "package": "openshift-service-mesh/pilot-rhel8:1777319850"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8490",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/kiali-rhel9:1776151270"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9448",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1776238635"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.1",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9448",
        "cpe": "cpe:/a:redhat:service_mesh:3.1::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1776256858"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8491",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/kiali-rhel9:1776149682"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9453",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-cni-rhel9:1776178280"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.2",
        "release_date": "2026-04-21T00:00:00Z",
        "advisory": "RHSA-2026:9453",
        "cpe": "cpe:/a:redhat:service_mesh:3.2::el9",
        "package": "openshift-service-mesh/istio-pilot-rhel9:1776178059"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 3.3",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8493",
        "cpe": "cpe:/a:redhat:service_mesh:3.3::el9",
        "package": "openshift-service-mesh/kiali-rhel9:1776151277"
      },
      {
        "product_name": "Red Hat Quay 3.1",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11916",
        "cpe": "cpe:/a:redhat:quay:3.10::el8",
        "package": "quay/quay-rhel8:1776736910"
      },
      {
        "product_name": "Red Hat Quay 3.1",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22840",
        "cpe": "cpe:/a:redhat:quay:3.10::el8",
        "package": "quay/quay-rhel8:1779822261"
      },
      {
        "product_name": "Red Hat Quay 3.12",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11856",
        "cpe": "cpe:/a:redhat:quay:3.12::el8",
        "package": "quay/quay-rhel8:1776752646"
      },
      {
        "product_name": "Red Hat Quay 3.12",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22629",
        "cpe": "cpe:/a:redhat:quay:3.12::el8",
        "package": "quay/quay-rhel8:1779811412"
      },
      {
        "product_name": "Red Hat Quay 3.14",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:21017",
        "cpe": "cpe:/a:redhat:quay:3.14::el8",
        "package": "quay/quay-rhel8:1779689392"
      },
      {
        "product_name": "Red Hat Quay 3.15",
        "release_date": "2026-06-09T00:00:00Z",
        "advisory": "RHSA-2026:24853",
        "cpe": "cpe:/a:redhat:quay:3.15::el8",
        "package": "quay/quay-rhel8:1780891395"
      },
      {
        "product_name": "Red Hat Quay 3.16",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19375",
        "cpe": "cpe:/a:redhat:quay:3.16::el9",
        "package": "quay/quay-rhel9:1779204086"
      },
      {
        "product_name": "Red Hat Quay 3.17",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22465",
        "cpe": "cpe:/a:redhat:quay:3.17::el9",
        "package": "quay/quay-rhel9:1779922205"
      },
      {
        "product_name": "Red Hat Quay 3.18",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:48085",
        "cpe": "cpe:/a:redhat:quay:3.18::el9",
        "package": "quay/quay-rhel9:1784987273"
      },
      {
        "product_name": "Red Hat Quay 3.9",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:11996",
        "cpe": "cpe:/a:redhat:quay:3.9::el8",
        "package": "quay/quay-rhel8:1776782369"
      },
      {
        "product_name": "Red Hat Quay 3.9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23361",
        "cpe": "cpe:/a:redhat:quay:3.9::el8",
        "package": "quay/quay-rhel8:1779811473"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10125",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/client-server-rhel9:1776339099"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10130",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/cosign-rhel9:1776329867"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24471",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/rhtas-console-rhel9:1780386299"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24475",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/createtree-rhel9:1780053572"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24477",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/rekor-monitor-rhel9:1780046753"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24479",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/fulcio-rhel9:1780046765"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24479",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/rekor-backfill-redis-rhel9:1780049214"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24479",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/rekor-server-rhel9:1780049214"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24479",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/timestamp-authority-rhel9:1780051354"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24479",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/trillian-database-rhel9:1780053572"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24479",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/trillian-logserver-rhel9:1780053572"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24479",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/trillian-logsigner-rhel9:1780053572"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24482",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/fetch-tsa-certs-rhel9:1780051354"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24482",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/gitsign-rhel9:1780052587"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24482",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/rekor-cli-rhel9:1780049214"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.3",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24482",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.3::el9",
        "package": "rhtas/updatetree-rhel9:1780053572"
      }
    ],
    "package_state": [
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "assisted/agent-preinstall-image-builder-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "rhai/assisted-installer-controller-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "rhai/assisted-installer-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/cert-manager-istio-csr-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/cert-manager-operator-bundle",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/cert-manager-operator-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/jetstack-cert-manager-acmesolver-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/jetstack-cert-manager-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "openshift-sandboxed-containers/osc-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/bitwarden-sdk-server-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-operator-bundle",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-operator-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "Kernel Module Management Operator for Red Hat Openshift",
        "fix_state": "Affected",
        "package_name": "kmm/kernel-module-management-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:kernel_module_management:2"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/loki-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/loki-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/lokistack-gateway-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/opa-openshift-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Not affected",
        "package_name": "lvms4/lvms-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-log-reader-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Will not fix",
        "package_name": "mtv-candidate/mtv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/cluster-api-provider-aws-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Under investigation",
        "package_name": "multicluster-engine/hive-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/hypershift-rhel9-operator",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/image-based-install-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/kube-rbac-proxy-mce-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-kessel-inventory-api-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Not affected",
        "package_name": "network-observability/network-observability-cli-rhel9",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/node-healthcheck-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-jenkins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/openshift-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-cache-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-chains-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-cli-tkn-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-opc-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-results-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-results-watcher-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-sidecarlogresults-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-ekb-dispatcher-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-ekb-kafka-controller-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-ekb-receiver-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-eventing-apiserver-receive-adapter-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-eventing-channel-controller-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-eventing-channel-dispatcher-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-eventing-controller-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-eventing-filter-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-eventing-ingress-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-eventing-jobsink-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-eventing-mtchannel-broker-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-eventing-mtping-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-eventing-webhook-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/kn-plugin-event-sender-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/serverless-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-proxyv2-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Will not fix",
        "package_name": "openshift-service-mesh/kiali-operator-bundle",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Will not fix",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Power monitoring for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-power-monitoring/power-monitoring-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_power_monitoring"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-grafana-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/acm-multicluster-observability-addon-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/kube-rbac-proxy-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/kube-state-metrics-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/submariner-operator-bundle",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-rhel8-operator",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/aap-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/aap-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-on-clouds/aoc-azure-aap-installer-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Build of Kueue",
        "fix_state": "Not affected",
        "package_name": "kueue/kueue-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:kueue_operator:1"
      },
      {
        "product_name": "Red Hat Build of Podman Desktop",
        "fix_state": "Affected",
        "package_name": "podman-desktop-macos-1-0",
        "cpe": "cpe:/a:redhat:podman_desktop:1"
      },
      {
        "product_name": "Red Hat Build of Podman Desktop",
        "fix_state": "Affected",
        "package_name": "podman-desktop-windows-1-0",
        "cpe": "cpe:/a:redhat:podman_desktop:1"
      },
      {
        "product_name": "Red Hat Build of Podman Desktop - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "rhdesktop/rh-podman-desktop-ext-bootc-rhel10",
        "cpe": "cpe:/a:redhat:podman_desktop:0"
      },
      {
        "product_name": "Red Hat Build of Podman Desktop - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "rhdesktop/rh-podman-desktop-ext-rhel-rhel10",
        "cpe": "cpe:/a:redhat:podman_desktop:0"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Affected",
        "package_name": "rhcl-1/authorino-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Will not fix",
        "package_name": "ignition",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Will not fix",
        "package_name": "rhel10/bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Will not fix",
        "package_name": "rhel10-eus/rhel-10.0-bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "grafana",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "ignition",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "rhel9/bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "rhel9-eus/rhel-9.6-bootc-image-builder",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-argoexec-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-argoexec-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-maas-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-launcher-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mod-arch-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/rhai-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Cluster Manager CLI",
        "fix_state": "Affected",
        "package_name": "ocm-cli-clients/ocm-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_cluster_manager_cli:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "cri-o",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "lvms4/lvms-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/cnf-tests-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/cnf-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/kube-compare-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/lifecycle-agent-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/network-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/numaresources-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-csr-approver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-orchestrator-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-aws-cluster-api-controllers-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-aws-pod-identity-webhook-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-baremetal-installer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-cli-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-driver-shared-resource-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-deployer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-builder",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-builder-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-helm-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-installer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-local-storage-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-os-images-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ovn-kubernetes-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-secrets-store-csi-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ptp-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift-clients",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift-kni/commatrix",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "podman",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "redhat/redhat-operator-index",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "skopeo",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Affected",
        "package_name": "odf4/mcg-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/oauth2-proxy-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/udi-base-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/udi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Not affected",
        "package_name": "openshift4-wincw/windows-machine-config-operator-bundle",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Not affected",
        "package_name": "openshift4-wincw/windows-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/argocd-agent-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/argocd-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/argocd-rhel9",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift on AWS",
        "fix_state": "Affected",
        "package_name": "rosa",
        "cpe": "cpe:/a:redhat:openshift_service_on_aws:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/kubevirt-tekton-tasks-create-datavolume-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/virt-cdi-apiserver-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/virt-cdi-cloner-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/virt-cdi-controller-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/virt-cdi-importer-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/virt-cdi-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/virt-cdi-uploadproxy-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/virt-cdi-uploadserver-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/openstack-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/openstack-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/prometheus-podman-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Will not fix",
        "package_name": "quay/clair-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/clair-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-builder-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-builder-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/certificate-transparency-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/ec-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/model-transparency-cli-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/policy-controller-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/policy-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Security Profiles Operator",
        "fix_state": "Affected",
        "package_name": "compliance/openshift-security-profiles-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_security_profiles_operator:1"
      },
      {
        "product_name": "Security Profiles Operator",
        "fix_state": "Affected",
        "package_name": "compliance/openshift-security-profiles-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift_security_profiles_operator:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-server-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Affected",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "zero-trust-workload-identity-manager/spiffe-spire-server-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-operator-bundle",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager - Tech Preview",
        "fix_state": "Will not fix",
        "package_name": "zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34986\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34986\nhttps://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8\nhttps://pkg.go.dev/github.com/go-jose/go-jose/v4#pkg-constants"
    ],
    "name": "CVE-2026-34986",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-03T21:14:09Z",
    "bugzilla": {
      "description": "cups: OpenPrinting CUPS: Privilege escalation via arbitrary file overwrite due to coerced authentication",
      "id": "2454947",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454947"
    },
    "cvss3": {
      "cvss3_base_score": "5.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-73",
    "details": [
      "OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. That token is enough to drive /admin/ requests on localhost, and the attacker can combine CUPS-Create-Local-Printer with printer-is-shared=true to persist a file:///... queue even though the normal FileDevice policy rejects such URIs. Printing to that queue gives an arbitrary root file overwrite; the PoC below uses that primitive to drop a sudoers fragment and demonstrate root command execution. At time of publication, there are no publicly available patches.",
      "A flaw was found in OpenPrinting CUPS. A local unprivileged user can exploit this vulnerability by coercing the `cupsd` service to authenticate to an attacker-controlled Internet Printing Protocol (IPP) service. This allows the user to create a persistent printer queue that can overwrite arbitrary files with root privileges. Successful exploitation can lead to privilege escalation and arbitrary root command execution."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8814",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "cups-main-2.4.17-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-34990\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34990\nhttps://github.com/OpenPrinting/cups/security/advisories/GHSA-c54j-2vqw-wpwp"
    ],
    "name": "CVE-2026-34990",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-01T11:48:13Z",
    "bugzilla": {
      "description": "corosync: Corosync: Denial of Service and information disclosure via crafted UDP packet",
      "id": "2453813",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453813"
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-253",
    "details": [
      "A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory contents",
      "A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory contents"
    ],
    "statement": "This vulnerability has a Moderate impact on Red Hat products. A flaw in Corosync's membership commit token sanity check, when running in the totemudp/totemudpu mode, allows a remote unauthenticated attacker to send a crafted UDP packet. This can lead to an out-of-bounds read, resulting in a denial of service and potential limited memory content disclosure. This issue affects Corosync only when configured to use the legacy totemudp or totemudpu transport modes with unencrypted communication.\nThese modes are not the default in modern Corosync versions. The default transport is knet, which supports encryption and is the standard configuration in RHEL.Additionally, totemudp and totemudpu are unsupported in RHEL, and their use requires explicit manual configuration.",
    "acknowledgement": "Red Hat would like to thank Sebastián Alba Vives for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13644",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "corosync-0:3.1.9-2.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19043",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "corosync-0:3.1.10-1.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14205",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "corosync-0:3.1.9-1.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20916",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "package": "corosync-0:2.4.5-7.el7_9.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13657",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "corosync-0:3.1.8-1.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14215",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "corosync-0:3.1.0-3.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14215",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "corosync-0:3.1.0-3.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14214",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "corosync-0:3.1.5-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14214",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "corosync-0:3.1.5-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14214",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "corosync-0:3.1.5-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14216",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "corosync-0:3.1.7-1.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14216",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "corosync-0:3.1.7-1.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13673",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "corosync-0:3.1.9-2.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19200",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "corosync-0:3.1.10-1.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14211",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "corosync-0:3.1.5-3.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14210",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "corosync-0:3.1.7-1.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14212",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "corosync-0:3.1.8-1.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14213",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "corosync-0:3.1.9-2.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35091\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35091\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2453169"
    ],
    "name": "CVE-2026-35091",
    "mitigation": {
      "value": "Systems using totemudp or totemudpu should migrate to the supported knet transport and enable encryption.\nDisabling the Corosync service is a valid workaround if clustering is not required, but for active clusters, enabling encryption via knet is the preferred and recommended approach.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-01T11:48:22Z",
    "bugzilla": {
      "description": "corosync: Corosync: Denial of Service via integer overflow in join message validation",
      "id": "2453814",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453814"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.",
      "A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode."
    ],
    "statement": "This is an Important denial of service vulnerability in Corosync, affecting deployments configured to use totemudp/totemudpu mode. A remote, unauthenticated attacker can send specially crafted UDP packets to trigger an integer overflow, causing the Corosync service to crash.This issue affects Corosync only when using the legacy totemudp or totemudpu transports with unencrypted communication. These are not the default.The default transport is knet, which supports encryption and is the standard configuration in RHEL.\nThe totemudp and totemudpu transports are unsupported in RHEL and require explicit manual configuration.",
    "acknowledgement": "Red Hat would like to thank Sebastián Alba Vives for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13644",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "corosync-0:3.1.9-2.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19043",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "corosync-0:3.1.10-1.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14205",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "corosync-0:3.1.9-1.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20916",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "package": "corosync-0:2.4.5-7.el7_9.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13657",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "corosync-0:3.1.8-1.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14215",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "corosync-0:3.1.0-3.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14215",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "corosync-0:3.1.0-3.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14214",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "corosync-0:3.1.5-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14214",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "corosync-0:3.1.5-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14214",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "corosync-0:3.1.5-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14216",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "corosync-0:3.1.7-1.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14216",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "corosync-0:3.1.7-1.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13673",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "corosync-0:3.1.9-2.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19200",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "corosync-0:3.1.10-1.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14211",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "corosync-0:3.1.5-3.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14210",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "corosync-0:3.1.7-1.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14212",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "corosync-0:3.1.8-1.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14213",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "corosync-0:3.1.9-2.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35092\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35092\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2453169"
    ],
    "name": "CVE-2026-35092",
    "mitigation": {
      "value": "Systems using totemudp or totemudpu should migrate to the supported knet transport and enable encryption.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-06T17:54:42Z",
    "bugzilla": {
      "description": "vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass",
      "id": "2455542",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455542"
    },
    "cvss3": {
      "cvss3_base_score": "4.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-22",
    "details": [
      "Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.",
      "A flaw was found in Vim's zip.vim plugin. A local user could be tricked into opening a specially crafted zip archive, which would allow a path traversal bypass. This vulnerability enables an attacker to overwrite arbitrary files on the system, potentially leading to data integrity issues or further system compromise."
    ],
    "statement": "There's a flaw in `zip.vim` plugin in Vim, allowing a local attacker to overwrite arbitrary files. A user must be tricked into opening a specially crafted zip archive for exploitation, potentially compromising data integrity or the system. When successfully exploited this vulnerability enables the attacker to overwrite arbitrary files or inject code in sensitive system's location, the impact of the exploitation depends on the privileges which the `vim` process is being executed. Sensitive or privileges files are only susceptible to be overwritten only if the `vim` process is being executed by a high privileged user.\nRed Hat Product Security team has rated this vulnerability as having a impact of MODERATE, this decision was made by the fact the user needs to be tricked to open a maliciously crafted file in order to a successful attack to be performed. Additionally the impact will be limited to files which the user running the `vim` process has write permissions.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22711",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "vim-2:9.1.083-9.el10_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30900",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22730",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-23.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22730",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-23.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33453",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33453",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34477",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34477",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34476",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34476",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22717",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22717",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28133",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "vim-2:8.2.2637-20.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:28049",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "vim-2:8.2.2637-20.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:28050",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "vim-2:8.2.2637-22.el9_6.3"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34102",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1782890503"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35177\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35177\nhttps://github.com/vim/vim/security/advisories/GHSA-jc86-w7vm-8p24"
    ],
    "name": "CVE-2026-35177",
    "mitigation": {
      "value": "Avoid opening untrusted zip archives with Vim. This operational control prevents the necessary user interaction required to trigger the path traversal vulnerability in the `zip.vim` plugin.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-05T14:50:29Z",
    "bugzilla": {
      "description": "Django: Django: Session theft due to improper cookie handling with cached pages",
      "id": "2466807",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466807"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-488",
    "details": [
      "An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.\nResponse headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Cantina for reporting this issue.",
      "A flaw was found in Django. When the `SESSION_SAVE_EVERY_REQUEST` setting is enabled, response headers do not properly vary on cookies for unmodified sessions. This vulnerability allows a remote attacker to steal a user's session after the user visits a cached public page, leading to unauthorized access to their account."
    ],
    "statement": "Moderate: A flaw in Django applications, when configured with `SESSION_SAVE_EVERY_REQUEST` enabled, allows for session theft. This occurs because response headers do not properly vary on cookies for unmodified sessions, enabling a remote attacker to steal a user's session after they visit a cached public page. This vulnerability requires a specific configuration and user interaction to be exploited.",
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "python-django20",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite-capsule:el8/python-django",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite:el8/python-django",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Update Infrastructure 4 for Cloud Providers",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:rhui:4::el8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35192\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35192\nhttps://docs.djangoproject.com/en/dev/releases/security/\nhttps://groups.google.com/g/django-announce\nhttps://www.djangoproject.com/weblog/2026/may/05/security-releases/"
    ],
    "name": "CVE-2026-35192",
    "mitigation": {
      "value": "To mitigate this issue, ensure that the `SESSION_SAVE_EVERY_REQUEST` setting in Django applications is set to `False` unless explicitly required for application functionality. Disabling this setting prevents the vulnerable condition where response headers do not properly vary on cookies for unmodified sessions on cached public pages. Consult your Django application's configuration for specific instructions on modifying this setting. A restart of the Django application or web server may be required for the change to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-03T13:16:38Z",
    "bugzilla": {
      "description": "django: Django: Information disclosure due to improper caching of authenticated responses",
      "id": "2484374",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484374"
    },
    "cvss3": {
      "cvss3_base_score": "3.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-524",
    "details": [
      "An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.\n`django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Shai Berger for reporting this issue.",
      "A flaw was found in Django. This vulnerability allows a remote attacker to read private cached responses. This occurs because the `UpdateCacheMiddleware` in Django does not correctly add the `Authorization` header to the `Vary` response header for requests that include an `Authorization` header but lack `Cache-Control: public`. Consequently, unauthenticated requests to the same URL can access sensitive cached information."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Self-service automation portal 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform/bootc-automation-portal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_portal:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35193\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35193\nhttps://docs.djangoproject.com/en/dev/releases/security/\nhttps://groups.google.com/g/django-announce\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/"
    ],
    "name": "CVE-2026-35193",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the length of a decoded SDL descriptor from a slice packet. A zero-length descriptor is later used to calculate the number of slice items, causing a division by zero. An unauthenticated attacker can exploit this by sending a crafted slice packet to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35215\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35215"
    ],
    "name": "CVE-2026-35215",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: InnoDB unspecified vulnerability (CPU Apr 2026)",
      "id": "2460325",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460325"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35236\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35236\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-35236",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: InnoDB unspecified vulnerability (CPU Apr 2026)",
      "id": "2460295",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460295"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35237\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35237\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-35237",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: InnoDB unspecified vulnerability (CPU Apr 2026)",
      "id": "2460316",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460316"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35238\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35238\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-35238",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: DML unspecified vulnerability (CPU Apr 2026)",
      "id": "2460323",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460323"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-772",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35239\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35239\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-35239",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T00:00:00Z",
    "bugzilla": {
      "description": "mysql: Optimizer unspecified vulnerability (CPU Apr 2026)",
      "id": "2460335",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460335"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server."
    ],
    "statement": "Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20693",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mysql8.4-0:8.4.9-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25919",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.0-8100020260609092222.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "mysql:8.4-8100020260526091138.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql-0:8.0.46-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25052",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mysql:8.4-9080020260602140041.rhel9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "mysql",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35240\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35240\nhttps://www.oracle.com/security-alerts/cpuapr2026.html\nhttps://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL"
    ],
    "name": "CVE-2026-35240",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-02T16:30:59Z",
    "bugzilla": {
      "description": "OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode",
      "id": "2454469",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454469"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-281",
    "details": [
      "In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).",
      "A flaw was found in OpenSSH. When the `scp` command is used by a root user to download a file with the legacy protocol option (`-O`) and without preserving original file permissions (`-p`), the downloaded file can be installed with elevated privileges (setuid or setgid). This unexpected behavior could allow a malicious file to execute with higher permissions than intended, posing a security risk through potential privilege escalation."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13380",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssh-0:9.9p1-14.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19069",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "openssh-0:9.9p1-23.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12389",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "openssh-0:9.9p1-7.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25063",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "openssh-0:5.3p1-125.el6_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22468",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "openssh-0:7.4p1-23.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13383",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "openssh-0:8.0p1-29.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13383",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "openssh-0:8.0p1-29.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22329",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "openssh-0:8.0p1-7.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22329",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "openssh-0:8.0p1-7.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21298",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "openssh-0:8.0p1-20.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21298",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "openssh-0:8.0p1-20.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13381",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssh-0:8.7p1-49.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19219",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssh-0:9.9p1-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13381",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssh-0:8.7p1-49.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19219",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssh-0:9.9p1-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22648",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "openssh-0:8.7p1-30.el9_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22564",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "openssh-0:8.7p1-38.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16059",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "openssh-0:8.7p1-45.el9_6.3"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26528",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202606140301-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26542",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202606160406-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28887",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202606231112-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:28962",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202606200237-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-06-18T00:00:00Z",
        "advisory": "RHSA-2026:25044",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202606051757-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34098",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202606250942-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25181",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202606051320-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20040",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202605201155-0"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30078",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1782352950"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30087",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1782352919"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30088",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782353093"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30089",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1782352847"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14937",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1778101579"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14937",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1778156756"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/hive-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Under investigation",
        "package_name": "openshift-pipelines/pipelines-resolvers-rhel9",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multicluster-operators-subscription-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35385\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35385\nhttps://marc.info/?l=openssh-unix-dev&m=177513443901484&w=2\nhttps://www.openssh.org/releasenotes.html#10.3p1\nhttps://www.openwall.com/lists/oss-security/2026/04/02/3"
    ],
    "name": "CVE-2026-35385",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-02T16:44:27Z",
    "bugzilla": {
      "description": "OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username",
      "id": "2454506",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454506"
    },
    "cvss3": {
      "cvss3_base_score": "3.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-78",
    "details": [
      "In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.",
      "A flaw was found in OpenSSH. This vulnerability allows a remote attacker to achieve arbitrary command execution by injecting shell metacharacters into a username provided on the command line. Exploitation requires an untrusted username and a non-default configuration of the '%' character in `ssh_config`."
    ],
    "statement": "Red Hat products do not ship in a configuration which is subject to this vulnerability. Additionally, the impact of the command execution is limited to the scope of the specific user account which users would need to create themselves.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13380",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssh-0:9.9p1-14.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19069",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "openssh-0:9.9p1-23.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12389",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "openssh-0:9.9p1-7.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13383",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "openssh-0:8.0p1-29.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13383",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "openssh-0:8.0p1-29.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22329",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "openssh-0:8.0p1-7.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22329",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "openssh-0:8.0p1-7.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21298",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "openssh-0:8.0p1-20.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21298",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "openssh-0:8.0p1-20.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13381",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssh-0:8.7p1-49.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19219",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssh-0:9.9p1-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13381",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssh-0:8.7p1-49.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19219",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssh-0:9.9p1-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22648",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "openssh-0:8.7p1-30.el9_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22564",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "openssh-0:8.7p1-38.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16059",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "openssh-0:8.7p1-45.el9_6.3"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14937",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1778101579"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35386\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35386\nhttps://marc.info/?l=openssh-unix-dev&m=177513443901484&w=2\nhttps://www.openssh.org/releasenotes.html#10.3p1\nhttps://www.openwall.com/lists/oss-security/2026/04/02/3"
    ],
    "name": "CVE-2026-35386",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-02T16:52:53Z",
    "bugzilla": {
      "description": "OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage",
      "id": "2454494",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454494"
    },
    "cvss3": {
      "cvss3_base_score": "3.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-115",
    "details": [
      "OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.",
      "A flaw was found in OpenSSH. This vulnerability allows the system to use unintended Elliptic Curve Digital Signature Algorithm (ECDSA) algorithms. This occurs because the configuration for accepted public key algorithms is misinterpreted, leading to the use of weaker cryptographic methods than intended. This could potentially allow an attacker to compromise the confidentiality of data."
    ],
    "statement": "The cipher choices which may be used as a result of this flaw may provide fewer bits of security than those configured by the user, however they are all still considered cryptographically secure. Users who work in regulated environments may however find themselves using ciphers which are not approved in their regulatory environment.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13380",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssh-0:9.9p1-14.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19069",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "openssh-0:9.9p1-23.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12389",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "openssh-0:9.9p1-7.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13383",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "openssh-0:8.0p1-29.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13383",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "openssh-0:8.0p1-29.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22329",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "openssh-0:8.0p1-7.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22329",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "openssh-0:8.0p1-7.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21298",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "openssh-0:8.0p1-20.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21298",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "openssh-0:8.0p1-20.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13381",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssh-0:8.7p1-49.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19219",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssh-0:9.9p1-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13381",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssh-0:8.7p1-49.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19219",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssh-0:9.9p1-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22648",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "openssh-0:8.7p1-30.el9_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22564",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "openssh-0:8.7p1-38.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16059",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "openssh-0:8.7p1-45.el9_6.3"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14937",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1778101579"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35387\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35387\nhttps://marc.info/?l=openssh-unix-dev&m=177513443901484&w=2\nhttps://www.openssh.org/releasenotes.html#10.3p1\nhttps://www.openwall.com/lists/oss-security/2026/04/02/3"
    ],
    "name": "CVE-2026-35387",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-02T16:57:31Z",
    "bugzilla": {
      "description": "OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions",
      "id": "2454500",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454500"
    },
    "cvss3": {
      "cvss3_base_score": "2.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-306",
    "details": [
      "OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.",
      "A flaw was found in OpenSSH. This vulnerability allows for a low integrity impact due to the omission of connection multiplexing confirmation for proxy-mode multiplexing sessions. A local user, under specific and complex conditions requiring user interaction, could potentially establish a multiplexed session without explicit confirmation, leading to unintended data handling."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13380",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssh-0:9.9p1-14.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19069",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "openssh-0:9.9p1-23.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12389",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "openssh-0:9.9p1-7.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13383",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "openssh-0:8.0p1-29.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13383",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "openssh-0:8.0p1-29.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22329",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "openssh-0:8.0p1-7.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22329",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "openssh-0:8.0p1-7.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21298",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "openssh-0:8.0p1-20.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21298",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "openssh-0:8.0p1-20.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13381",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssh-0:8.7p1-49.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19219",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssh-0:9.9p1-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13381",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssh-0:8.7p1-49.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19219",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssh-0:9.9p1-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22648",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "openssh-0:8.7p1-30.el9_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22564",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "openssh-0:8.7p1-38.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16059",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "openssh-0:8.7p1-45.el9_6.3"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14937",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1778101579"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14937",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1778156756"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35388\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35388\nhttps://marc.info/?l=openssh-unix-dev&m=177513443901484&w=2\nhttps://www.openssh.org/releasenotes.html#10.3p1\nhttps://www.openwall.com/lists/oss-security/2026/04/02/3"
    ],
    "name": "CVE-2026-35388",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-02T17:08:15Z",
    "bugzilla": {
      "description": "OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option",
      "id": "2454490",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454490"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-168",
    "details": [
      "OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.",
      "A flaw was found in OpenSSH. This vulnerability arises from the incorrect handling of the authorized_keys principals option in uncommon scenarios. Specifically, when a principals list is used with a Certificate Authority that includes comma characters, OpenSSH may misinterpret the input. This could lead to security bypasses, potentially allowing unintended access or information disclosure in specific authentication contexts."
    ],
    "statement": "The risk posed by this flaw to Red Hat products is limited. The use of SSH certificates is not enabled by default and requires that users opt-in to the feature. Further, when following documented guidance ssh connections should only be permitted to non-root users which will limit the impact of this flaw.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13380",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "openssh-0:9.9p1-14.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19069",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "openssh-0:9.9p1-23.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12389",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "openssh-0:9.9p1-7.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13383",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "openssh-0:8.0p1-29.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13383",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "openssh-0:8.0p1-29.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22329",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "openssh-0:8.0p1-7.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22329",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "openssh-0:8.0p1-7.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21398",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "openssh-0:8.0p1-15.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21298",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "openssh-0:8.0p1-20.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21298",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "openssh-0:8.0p1-20.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13381",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssh-0:8.7p1-49.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19219",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssh-0:9.9p1-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13381",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssh-0:8.7p1-49.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19219",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssh-0:9.9p1-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22648",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "openssh-0:8.7p1-30.el9_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22564",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "openssh-0:8.7p1-38.el9_4.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16059",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "openssh-0:8.7p1-45.el9_6.3"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14937",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1778101579"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35414\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35414\nhttps://marc.info/?l=openssh-unix-dev&m=177513443901484&w=2\nhttps://www.openssh.org/releasenotes.html#10.3p1\nhttps://www.openwall.com/lists/oss-security/2026/04/02/3"
    ],
    "name": "CVE-2026-35414",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-13T23:59:59Z",
    "bugzilla": {
      "description": "Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code",
      "id": "2457729",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457729"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.",
      "A flaw was found in the SPDY streaming code used by Kubelet, CRI-O, and kube-apiserver. An attacker with specific cluster roles, such as those allowing access to pod port forwarding, execution, or attachment, or node proxying, could exploit this vulnerability. This could lead to a Denial of Service (DoS) by causing the affected components to become unresponsive."
    ],
    "statement": "This is an Important denial of service flaw affecting OpenShift Container Platform. An attacker with specific elevated cluster roles, such as those permitting pod port forwarding, execution, attachment, or node proxying, could exploit a vulnerability in the SPDY streaming code of Kubelet, CRI-O, and kube-apiserver, leading to unresponsiveness of these critical components.",
    "affected_release": [
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34755",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift-0:4.19.0-202606301915.p2.g63adf01.assembly.stream.el9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:51422",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "microshift-0:4.19.42-202608062155.p0.g46c9d67.assembly.4.19.42.el9"
      },
      {
        "product_name": "RHEM 1.0 for RHEL 9",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36796",
        "cpe": "cpe:/a:redhat:edge_manager:1.0::el9",
        "package": "flightctl-0:1.0.3-1.el9em"
      },
      {
        "product_name": "RHEM 1.1 for RHEL 10",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:41019",
        "cpe": "cpe:/a:redhat:edge_manager:1.1::el10",
        "package": "flightctl-0:1.1.3-1.el10em"
      },
      {
        "product_name": "RHEM 1.1 for RHEL 9",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:41019",
        "cpe": "cpe:/a:redhat:edge_manager:1.1::el9",
        "package": "flightctl-0:1.1.3-1.el9em"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19099",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/assisted-service-9-rhel9:1779135478"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.11.0",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19108",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.11::el9",
        "package": "multicluster-engine/assisted-service-9-rhel9:1778892370"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17121",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el8",
        "package": "multicluster-engine/assisted-service-8-rhel8:1778288655"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:17123",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/assisted-service-9-rhel9:1778288646"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17704",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/multicloud-integrations-rhel9:1778264389"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17704",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/multicluster-operators-channel-rhel9:1778302921"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11070",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-roxctl-rhel8:1777307791"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11217",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
        "package": "advanced-cluster-security/rhacs-roxctl-rhel8:1777307791"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4.9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13791",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-roxctl-rhel8:1777986630"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.10",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13829",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.10::el8",
        "package": "advanced-cluster-security/rhacs-roxctl-rhel8:1777976489"
      },
      {
        "product_name": "Red Hat Container Native Virtualization 4.13",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53655",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4.13::el9",
        "package": "container-native-virtualization/virt-exportserver-rhel9:1786346620"
      },
      {
        "product_name": "Red Hat Container Native Virtualization 4.15",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36162",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4.15::el9",
        "package": "container-native-virtualization/virt-exportserver-rhel9:1783042900"
      },
      {
        "product_name": "Red Hat Container Native Virtualization 4.16",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33078",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4.16::el9",
        "package": "container-native-virtualization/virt-exportserver-rhel9:1782184329"
      },
      {
        "product_name": "Red Hat Container Native Virtualization 4.17",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33071",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4.17::el9",
        "package": "container-native-virtualization/virt-exportserver-rhel9:1782358244"
      },
      {
        "product_name": "Red Hat Container Native Virtualization 4.19",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27914",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4.19::el9",
        "package": "container-native-virtualization/virt-exportserver-rhel9:1781590993"
      },
      {
        "product_name": "Red Hat Container Native Virtualization 4.20",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27983",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4.20::el9",
        "package": "container-native-virtualization/virt-exportserver-rhel9:1781838712"
      },
      {
        "product_name": "Red Hat Container Native Virtualization 4.21",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27903",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4.21::el9",
        "package": "container-native-virtualization/virt-exportserver-rhel9:1782012918"
      },
      {
        "product_name": "Red Hat Container Native Virtualization 4.22",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27941",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4.22::el9",
        "package": "container-native-virtualization/virt-exportserver-rhel9:1781852593"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21697",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-sriov-network-config-daemon:1779716480"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21697",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-sriov-network-operator:1779716474"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21697",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-sriov-network-webhook:1779716476"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34050",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-node-feature-discovery:1782395416"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:40030",
        "cpe": "cpe:/a:redhat:openshift:4.12::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1784054795"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21692",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-sriov-network-config-daemon:1779889638"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21692",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-sriov-network-operator:1779889606"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21692",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-sriov-network-webhook:1779864381"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:40022",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1784056255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:40023",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "openshift4/ose-node-feature-discovery:1784055726"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25009",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-node-feature-discovery:1780956818"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25009",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-sriov-network-config-daemon:1780955979"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25009",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-sriov-network-operator:1781006909"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25009",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-sriov-network-webhook:1780956441"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-30T00:00:00Z",
        "advisory": "RHSA-2026:43253",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel8:1784582377"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:23235",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-node-feature-discovery-rhel9:1779915764"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:23235",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-sriov-network-config-daemon-rhel9:1779916110"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:23235",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-sriov-network-rhel9-operator:1779915561"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:23235",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-sriov-network-webhook-rhel9:1779915526"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-30T00:00:00Z",
        "advisory": "RHSA-2026:43227",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1784576933"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-05-29T00:00:00Z",
        "advisory": "RHSA-2026:20089",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-node-feature-discovery-rhel9:1779251341"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25046",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-sriov-network-config-daemon-rhel9:1780954827"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25046",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-sriov-network-rhel9-operator:1780954223"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25046",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-sriov-network-webhook-rhel9:1780955112"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:36621",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1782934190"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:36621",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1782904234"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17598",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1778707884"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17599",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-node-feature-discovery-rhel9:1778701022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34099",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1782187374"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34099",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1782189013"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34100",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9:1782186020"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34100",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-sriov-network-config-daemon-rhel9:1782186155"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34100",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-sriov-network-rhel9-operator:1782185537"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34100",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-sriov-network-webhook-rhel9:1782186155"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:47728",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1784313542"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:47729",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1784319218"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:12118",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1777070108"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17449",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-node-feature-discovery-rhel9:1778521451"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21658",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-sriov-network-config-daemon-rhel9:1779779708"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21658",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-sriov-network-rhel9-operator:1779780608"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:21658",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-sriov-network-webhook-rhel9:1779780022"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:29857",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1782175121"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:29857",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1782173522"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:29858",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9:1782190146"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:37193",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1783084308"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:40828",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1783702867"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:51013",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1785655390"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20041",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1779251684"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20042",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-node-feature-discovery-rhel9:1779252023"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20042",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-sriov-network-config-daemon-rhel9:1779250076"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20042",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-sriov-network-rhel9-operator:1779249730"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20042",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-sriov-network-webhook-rhel9:1779249801"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25201",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1781002119"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:27004",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1781557059"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:29865",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9:1782189936"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:34766",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1782871003"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:34766",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-hyperkube-rhel9:1782879945"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:37580",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-ebs-csi-driver-rhel9:1783358181"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:37581",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-container-rhel9:1783088446"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:51007",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1785600792"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17468",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1778138337"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17469",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-node-feature-discovery-rhel9:1778522102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:25194",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1781023952"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:27063",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1781196883"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:29801",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9:1781844985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:34791",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1782865684"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:37629",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-container-rhel9:1783419985"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.2",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:51022",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "openshift4/ose-ovn-kubernetes-rhel9:1785857530"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:17475",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-node-feature-discovery-rhel9:1778164872"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20034",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-powervs-block-csi-driver-rhel9:1779250427"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:25187",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-cluster-node-tuning-rhel9-operator:1780973735"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:25187",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-openshift-apiserver-rhel9:1780979102"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:29835",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9:1782311084"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:34769",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1782861857"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:37187",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-container-rhel9:1783090488"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:44267",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1784548626"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:25207",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "openshift4/ose-aws-efs-csi-driver-container-rhel9:1781103659"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:27010",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "openshift4/ose-smb-csi-driver-rhel9:1781640970"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:29795",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "openshift4/ose-csi-external-provisioner-rhel9:1782109368"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:34794",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "openshift4/ose-azure-disk-csi-driver-rhel9:1782878115"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:34794",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "openshift4/ose-csi-node-driver-registrar-rhel9:1782878255"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:44237",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "openshift4/ose-ovn-kubernetes-microshift-rhel9:1784702398"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9:1786705347"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9-operator:1786706101"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-core-rhel9:1786705558"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-rhel9-operator:1786705646"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-console-rhel9:1786706138"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-rhel9-operator:1786705741"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1786705777"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-rhel9-operator:1786705802"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cli-rhel9:1786705938"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-console-rhel9:1786706577"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1786706125"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1786706177"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1786706188"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1786706679"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1786706357"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-must-gather-rhel9:1786706612"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-rhel9-operator:1786706644"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odr-rhel9-operator:1786706659"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1786706880"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/cephcsi-rhel9:1782932114"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/cephcsi-rhel9-operator:1782931768"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/devicefinder-rhel9:1782932104"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/mcg-core-rhel9:1783536000"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/mcg-rhel9-operator:1783535989"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-client-console-rhel9:1783536515"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-client-rhel9-operator:1782932521"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1783018461"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/ocs-rhel9-operator:1783018421"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-blackbox-exporter-rhel9:1782932812"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cli-rhel9:1783537001"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1782932919"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-console-rhel9:1783537586"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1782932969"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1782933015"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1782933042"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-drbd-rhel9:1783537392"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-external-snapshotter-rhel9-operator:1782933235"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-external-snapshotter-sidecar-rhel9:1782933251"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1783537955"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1782933417"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-must-gather-rhel9:1783537742"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odf-rhel9-operator:1782933602"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-rhel9-operator:1783019377"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-volsync-plugin-mover-rhel9:1782934054"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/odr-volsync-plugin-rhel9-operator:1782934036"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.22",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37387",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.22::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1782934284"
      }
    ],
    "package_state": [
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/cert-manager-operator-bundle",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/cert-manager-operator-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/jetstack-cert-manager-acmesolver-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "cert-manager Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "cert-manager/jetstack-cert-manager-rhel9",
        "cpe": "cpe:/a:redhat:cert_manager:1"
      },
      {
        "product_name": "Dynamic Accelerator Slicer Operator for Red Hat OpenShift",
        "fix_state": "Will not fix",
        "package_name": "dynamic-accelerator-slicer-tech-preview/instaslice-daemonset-rhel9",
        "cpe": "cpe:/a:redhat:dynamic_accelerator_slicer:1"
      },
      {
        "product_name": "Dynamic Accelerator Slicer Operator for Red Hat OpenShift",
        "fix_state": "Will not fix",
        "package_name": "dynamic-accelerator-slicer-tech-preview/instaslice-operator-bundle",
        "cpe": "cpe:/a:redhat:dynamic_accelerator_slicer:1"
      },
      {
        "product_name": "Dynamic Accelerator Slicer Operator for Red Hat OpenShift",
        "fix_state": "Will not fix",
        "package_name": "dynamic-accelerator-slicer-tech-preview/instaslice-rhel9-operator",
        "cpe": "cpe:/a:redhat:dynamic_accelerator_slicer:1"
      },
      {
        "product_name": "Dynamic Accelerator Slicer Operator for Red Hat OpenShift",
        "fix_state": "Will not fix",
        "package_name": "dynamic-accelerator-slicer-tech-preview/instaslice-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:dynamic_accelerator_slicer:1"
      },
      {
        "product_name": "Dynamic Accelerator Slicer Operator for Red Hat OpenShift",
        "fix_state": "Will not fix",
        "package_name": "dynamic-accelerator-slicer-tech-preview/instaslice-webhook-rhel9",
        "cpe": "cpe:/a:redhat:dynamic_accelerator_slicer:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/bitwarden-sdk-server-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-operator-bundle",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-operator-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Not affected",
        "package_name": "lvms4/lvms-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Not affected",
        "package_name": "lvms4/lvms-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Not affected",
        "package_name": "lvms4/lvms-operator-bundle",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Not affected",
        "package_name": "lvms4/lvms-rhel9-operator",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/cluster-api-provider-kubevirt-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/cluster-curator-controller-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/hive-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/hypershift-rhel9-operator",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/image-based-install-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/must-gather-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multicluster-operators-subscription-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-main-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-rhel8-operator",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-scanner-v4-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "cri-o",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "lvms4/lvms-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/cnf-tests-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4-dev-preview-beta/openperouter-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4-dev-preview-beta/openperouter-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/kubevirt-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/microshift-bootc-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/noderesourcetopology-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/numaresources-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/numaresources-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/numaresources-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/openshift-route-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-aws-cloud-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-cloud-controller-manager-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-azure-cloud-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-cloud-node-manager-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-azure-cloud-node-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-disk-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-file-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-file-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-autoscaler-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-capacity-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-kube-apiserver-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-kube-apiserver-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-policy-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-driver-manila-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-driver-manila-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-csi-driver-nfs-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-dpu-cni-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-dpu-daemon-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-dpu-intel-ipu-p4sdk-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-dpu-intel-ipu-vsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-dpu-intel-netsec-vsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-dpu-marvell-cp-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-dpu-marvell-vsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-dpu-network-resources-injector-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-dpu-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-gcp-cloud-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ibm-vpc-block-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-kube-proxy-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-config-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-multus-cni-microshift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-multus-cni-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openshift-controller-manager-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openshift-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-openstack-cinder-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openstack-cinder-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-openstack-cloud-controller-manager-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-openstack-cloud-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-sriov-network-device-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-sriov-network-metrics-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vmware-vsphere-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-vmware-vsphere-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-syncer-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-syncer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/sriov-network-metrics-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4-wincw/windows-machine-config-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4-wincw/windows-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ztp-site-generate-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3",
        "fix_state": "Not affected",
        "package_name": "rhosdt/opentelemetry-collector-rhel9",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Affected",
        "package_name": "openshift4-wincw/windows-machine-config-operator-bundle",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Affected",
        "package_name": "openshift4-wincw/windows-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/argo-rollouts-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/libguestfs-tools-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/multus-dynamic-networks-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/passt-network-binding-plugin-cni-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/passt-network-binding-plugin-sidecar-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/pr-helper-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/sidecar-shim-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-api-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-artifacts-server-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-controller-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-exportproxy-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-handler-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-launcher-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Affected",
        "package_name": "container-native-virtualization/virt-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/wasp-agent-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Zero Trust Workload Identity Manager",
        "fix_state": "Not affected",
        "package_name": "zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9",
        "cpe": "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35469\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35469"
    ],
    "name": "CVE-2026-35469",
    "mitigation": {
      "value": "To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-03T02:25:57Z",
    "bugzilla": {
      "description": "tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments",
      "id": "2454716",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454716"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-88",
    "details": [
      "In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.",
      "A flaw was found in Tornado. A remote attacker could exploit this vulnerability by injecting specially crafted characters into the `domain`, `path`, and `samesite` arguments when setting cookies. This could lead to cookie attribute injection, potentially allowing for information disclosure or manipulation of client-side data."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13641",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "python-tornado-0:6.5.5-1.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19034",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "python-tornado-0:6.5.5-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20577",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "python-tornado-0:6.4.2-1.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24342",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "python-tornado-0:4.2.1-5.el7_9.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13670",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python-tornado-0:6.5.5-1.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19189",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python-tornado-0:6.5.5-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20573",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "python-tornado-0:6.4.2-1.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20810",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "python-tornado-0:6.4.2-1.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20572",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "python-tornado-0:6.4.2-2.el9_6.3"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-llama-stack-core-rhel9:1782471587"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9:1782471606"
      }
    ],
    "package_state": [
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "external-secrets-operator/bitwarden-sdk-server-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "external-secrets-operator/external-secrets-operator-bundle",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "external-secrets-operator/external-secrets-operator-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "pcs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "pcs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/disk-image-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "python-pep517",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "python-tornado",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-35536\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35536\nhttps://github.com/tornadoweb/tornado/releases/tag/v6.5.5\nhttps://github.com/tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7"
    ],
    "name": "CVE-2026-35536",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-26T03:44:20Z",
    "bugzilla": {
      "description": "bind: Amplification vulnerabilities via self-pointed glue records",
      "id": "2479768",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2479768"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack.  If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources.\nThis issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.",
      "A flaw was found in BIND resolvers. A remote attacker could exploit this vulnerability by sending a query to a specially crafted zone. This would cause the resolver to consume disproportionate resources, leading to a denial of service (DoS) due to resource exhaustion."
    ],
    "statement": "Moderate: This vulnerability in BIND resolvers allows for an amplified resource consumption attack. A specially crafted DNS zone can cause a Red Hat system acting as a resolver to consume excessive resources, potentially leading to a denial of service.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-21T00:00:00Z",
        "advisory": "RHSA-2026:20334",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "bind-main-9.18.49-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "bind9.16",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "bind",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "bind9.18",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "dhcp",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-3592\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-3592"
    ],
    "name": "CVE-2026-3592",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-06T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "['Hi,\\n\\nI would like to disclose CVE-2026-36849, a denial of service vulnerability\\nin libtiff.\\n\\n== Summary ==\\n\\nAn issue in libtiff v4.7.1 allows an attacker to cause a denial of service\\nvia a crafted TIFF file containing a large SamplesPerPixel tag value.\\n\\n== Affected Versions ==\\n\\nlibtiff v4.7.1 and prior\\n\\n== Patch ==', '== References ==\\n\\n- CVE: CVE-2026-36849\\n- Issue:', 'Regards,\\nSatriyo Utomo\\n(aleens-lab)']"
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-36849\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-36849"
    ],
    "name": "CVE-2026-36849",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-08T10:32:19Z",
    "bugzilla": {
      "description": "libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handler",
      "id": "2445579",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445579"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.",
      "A flaw was found in libssh. A remote attacker could trigger an out-of-bounds read vulnerability in the SFTP Extension Name Handler by manipulating the `idx` argument in the `sftp_extensions_get_name` or `sftp_extensions_get_data` functions. This could lead to a Denial of Service (DoS), making the affected system unresponsive."
    ],
    "statement": "A MODERATE impact out-of-bounds read vulnerability exists in libssh's SFTP extension. A remote attacker could exploit this flaw by manipulating an argument to the `sftp_extensions_get_name/sftp_extensions_get_data` functions, potentially leading to a denial of service or information disclosure. This affects Red Hat Enterprise Linux versions utilizing libssh.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7067",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libssh-main-0.12.0-1.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-3731\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-3731\nhttps://gitlab.com/libssh/libssh-mirror/-/commit/855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60\nhttps://vuldb.com/?ctiid.349709\nhttps://vuldb.com/?id.349709\nhttps://vuldb.com/?submit.767120\nhttps://www.libssh.org/files/0.12/libssh-0.12.0.tar.xz\nhttps://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt"
    ],
    "name": "CVE-2026-3731",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-11T10:09:08Z",
    "bugzilla": {
      "description": "curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect",
      "id": "2446450",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
    },
    "cvss3": {
      "cvss3_base_score": "5.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-201",
    "details": [
      "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.",
      "A flaw was found in curl. When an OAuth2 bearer token is used for an HTTP(S) transfer that redirects to a second URL, curl could unintentionally leak the token. This occurs if the second hostname has entries in the `.netrc` file, allowing the bearer token intended for the first host to be sent to the redirected host. This information disclosure could allow an attacker to gain unauthorized access."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55450",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "curl-0:8.12.1-4.el10_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55439",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "curl-0:7.76.1-40.el9_8.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55439",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "curl-0:7.76.1-40.el9_8.5"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6893",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.19.0-3.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/recert-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Fix deferred",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-3783\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-3783\nhttp://www.openwall.com/lists/oss-security/2026/03/11/2\nhttps://curl.se/docs/CVE-2026-3783.html\nhttps://curl.se/docs/CVE-2026-3783.json\nhttps://hackerone.com/reports/3583983"
    ],
    "name": "CVE-2026-3783",
    "mitigation": {
      "value": "To prevent the leakage of OAuth2 bearer tokens, ensure that `.netrc` files are carefully managed. Avoid configuring `.netrc` entries for untrusted or unknown hostnames, particularly when `curl` is used with OAuth2 bearer tokens and is configured to follow redirects. Regularly review and restrict the scope of credentials stored in `.netrc` files to only explicitly trusted destinations.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-11T10:09:21Z",
    "bugzilla": {
      "description": "curl: curl: Unauthorized access due to improper HTTP proxy connection reuse",
      "id": "2446449",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446449"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-305",
    "details": [
      "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
      "A flaw was found in curl. This vulnerability allows curl to wrongly reuse an existing HTTP proxy connection when performing a CONNECT request to a server, even if the new request uses different authentication credentials for the HTTP proxy. This improper connection reuse could lead to an attacker gaining unauthorized access to resources or information intended for a different user."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55450",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "curl-0:8.12.1-4.el10_2.3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-07T00:00:00Z",
        "advisory": "RHSA-2026:6893",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.19.0-3.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/recert-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Fix deferred",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-3784\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-3784\nhttp://www.openwall.com/lists/oss-security/2026/03/11/3\nhttps://curl.se/docs/CVE-2026-3784.html\nhttps://curl.se/docs/CVE-2026-3784.json\nhttps://hackerone.com/reports/3584903"
    ],
    "name": "CVE-2026-3784",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-09T00:00:00Z",
    "bugzilla": {
      "description": "jbig2dec: jbig2dec: Denial of Service via crafted input",
      "id": "2498866",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498866"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "A flaw was found in jbig2dec. An integer overflow vulnerability in the `jbig2_arith_iaid_ctx_new()` function allows a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted input. This can lead to the affected system becoming unresponsive or crashing, disrupting its normal operation."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jbig2dec",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jbig2dec",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jbig2dec",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-38076\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-38076\nhttp://artifex.com\nhttps://gist.github.com/dkjsone/c237b83ffa9ebd7028b5db7f410fcf78\nhttps://github.com/ArtifexSoftware/jbig2dec"
    ],
    "name": "CVE-2026-38076",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-30T17:29:25Z",
    "bugzilla": {
      "description": "gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response",
      "id": "2445762",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445762"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-179",
    "details": [
      "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.",
      "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust."
    ],
    "statement": "This issue has a LOW impact. A flaw in gnutls' OCSP stapling implementation allows a client with OCSP verification enabled to accept a revoked server certificate. This occurs when a multi-record OCSP response is stapled, and the client incorrectly reads the certificate status from an unrelated record, leading to an order-dependent acceptance of a revoked certificate.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20613",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gnutls-0:3.8.10-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26409",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gnutls-0:3.8.9-9.el10_0.19"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:13274",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gnutls-main-3.8.13-1.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-3832\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-3832\nhttps://gitlab.com/gnutls/gnutls/-/issues/1801"
    ],
    "name": "CVE-2026-3832",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-15T00:00:00Z",
    "bugzilla": {
      "description": "busybox: BusyBox: Denial of Service via crafted AWK script",
      "id": "2501204",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501204"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.",
      "A flaw was found in BusyBox. This vulnerability, a stack overflow in the evaluate() function, allows a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted AWK script. A Denial of Service attack can make the affected system or application unavailable to legitimate users."
    ],
    "statement": "This Moderate flaw in BusyBox's AWK interpreter allows a denial of service. An attacker could provide a specially crafted AWK script, leading to a stack overflow and making the BusyBox instance unresponsive. This vulnerability primarily affects systems where BusyBox is configured to execute untrusted AWK scripts, limiting its broader impact.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42074",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "busybox-main-1.37.0-8.2.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "busybox",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-38752\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-38752\nhttp://busybox.com\nhttps://lists.busybox.net/pipermail/busybox/2026-June/092351.html"
    ],
    "name": "CVE-2026-38752",
    "mitigation": {
      "value": "For systems utilizing BusyBox, limit exposure by avoiding the execution of untrusted AWK scripts. Ensure that BusyBox instances are not configured to process arbitrary or untrusted AWK script input, particularly in environments where BusyBox is used for critical system functions.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-15T00:00:00Z",
    "bugzilla": {
      "description": "busybox: Busybox: Denial of Service via crafted AWK script in awk_sub() function",
      "id": "2501183",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501183"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.",
      "A flaw was found in Busybox. A use-after-free vulnerability in the awk_sub() function allows a remote attacker to cause a Denial of Service (DoS) by supplying a specially crafted AWK script. This can lead to the unavailability of the Busybox service."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:41130",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "busybox-main-1.37.0-8.1.hum1",
        "impact": "important"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-38753\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-38753\nhttp://busybox.com\nhttps://lists.busybox.net/pipermail/busybox/2026-June/092352.html"
    ],
    "name": "CVE-2026-38753",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "5.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-38754\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-38754"
    ],
    "name": "CVE-2026-38754",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-15T00:00:00Z",
    "bugzilla": {
      "description": "busybox: Busybox: Denial of Service via heap overflow in evalcommand() function",
      "id": "2501194",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501194"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.",
      "A flaw was found in Busybox. A heap overflow vulnerability in the `evalcommand()` function allows attackers to cause a Denial of Service (DoS) by supplying a specially crafted input. This can lead to the unavailability of the service."
    ],
    "statement": "This Moderate impact flaw in Busybox's `evalcommand()` function can lead to a Denial of Service. The vulnerability requires an attacker to supply specially crafted input, which typically implies existing local access or specific application interactions within the Busybox environment, thus limiting the direct exposure.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42074",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "busybox-main-1.37.0-8.2.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "busybox",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-38755\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-38755\nhttps://busybox.com\nhttps://lists.busybox.net/pipermail/busybox/2026-June/092354.html"
    ],
    "name": "CVE-2026-38755",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-07T16:59:23Z",
    "bugzilla": {
      "description": "cups: CUPS: Denial of Service via integer underflow in IPP attribute handling",
      "id": "2456107",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456107"
    },
    "cvss3": {
      "cvss3_base_score": "4.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-191",
    "details": [
      "OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, an integer underflow vulnerability in _ppdCreateFromIPP() (cups/ppd-cache.c) allows any unprivileged local user to crash the cupsd root process by supplying a negative job-password-supported IPP attribute. The bounds check only caps the upper bound, so a negative value passes validation, is cast to size_t (wrapping to ~2^64), and is used as the length argument to memset() on a 33-byte stack buffer. This causes an immediate SIGSEGV in the cupsd root process. Combined with systemd's Restart=on-failure, an attacker can repeat the crash for sustained denial of service.",
      "A flaw was found in CUPS, an open-source printing system. An unprivileged local user can exploit an integer underflow vulnerability by providing a negative job-password-supported Internet Printing Protocol (IPP) attribute. This manipulation causes the cupsd root process to crash, which can be repeatedly triggered to achieve a sustained Denial of Service (DoS) on the system."
    ],
    "statement": "This Moderate impact vulnerability in CUPS allows an unprivileged local user to trigger a denial of service by providing a specially crafted IPP attribute. This can repeatedly crash the `cupsd` root process, leading to a sustained denial of service on Red Hat Enterprise Linux systems where CUPS is enabled.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8814",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "cups-main-2.4.17-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-39314\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-39314\nhttps://github.com/OpenPrinting/cups/security/advisories/GHSA-pp8w-2g52-7vj7"
    ],
    "name": "CVE-2026-39314",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-07T17:00:26Z",
    "bugzilla": {
      "description": "cups: CUPS: Denial of Service and potential arbitrary code execution via use-after-free vulnerability when deleting temporary printers.",
      "id": "2456120",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456120"
    },
    "cvss3": {
      "cvss3_base_score": "4.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a use-after-free vulnerability exists in the CUPS scheduler (cupsd) when temporary printers are automatically deleted. cupsdDeleteTemporaryPrinters() in scheduler/printers.c calls cupsdDeletePrinter() without first expiring subscriptions that reference the printer, leaving cupsd_subscription_t.dest as a dangling pointer to freed heap memory. The dangling pointer is subsequently dereferenced at multiple code sites, causing a crash (denial of service) of the cupsd daemon. With heap grooming, this can be leveraged for code execution.",
      "A flaw was found in CUPS, an open-source printing system. This vulnerability, known as a use-after-free, occurs in the CUPS scheduler when temporary printers are automatically removed. The system fails to properly manage memory, leaving a pointer to a freed memory location. An attacker could exploit this to cause the CUPS daemon to crash, leading to a denial of service. In more severe scenarios, this could potentially allow an attacker to execute arbitrary code."
    ],
    "statement": "This Moderate impact vulnerability in CUPS arises from a use-after-free flaw within the scheduler when temporary printers are automatically deleted. Exploitation could lead to a denial of service of the CUPS daemon, and potentially arbitrary code execution. This affects Red Hat systems running CUPS where temporary printers are configured or utilized.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8814",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "cups-main-2.4.17-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-39316\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-39316\nhttps://github.com/OpenPrinting/cups/security/advisories/GHSA-pjv5-prqp-46rg"
    ],
    "name": "CVE-2026-39316",
    "mitigation": {
      "value": "To mitigate this issue, restrict network access to the CUPS daemon to only trusted hosts or localhost. This can be achieved by configuring firewall rules to block access to TCP port 631 from untrusted networks. For example, using `firewalld`:\n`sudo firewall-cmd --permanent --zone=public --remove-port=631/tcp`\n`sudo firewall-cmd --reload`\nAlternatively, configure CUPS to only listen on localhost by modifying the `Listen` directive in `/etc/cups/cupsd.conf` to `Listen localhost:631`. After modifying the configuration, the CUPS service must be restarted for changes to take effect, which may temporarily interrupt printing services:\n`sudo systemctl restart cups`",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-18T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an unprivileged user to delete OVS-attached network interfaces belonging to other users. When lxc-user-nic delete scans its NIC database to authorize a deletion request, the interface name comparison can set the authorization flag based on a name match alone, even when the ownership, type, and link fields in that database entry belong to a different user. The vulnerable check sits after the goto next label handling, meaning it is reachable on lines where earlier ownership checks failed or were skipped. Because nothing downstream of this authorization signal re-verifies that the matched database line actually belongs to the caller, an unprivileged attacker with a valid lxc-usernet policy entry can trigger deletion of another user's OVS port on the same bridge. \n\nThis is limited to multi-tenant environments using lxc-user-nic with OpenVSwitch bridges. The impact is denial of service - one tenant can repeatedly disconnect networking from containers run by another tenant on shared infrastructure. This is patched in version 7.0.0."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-39402\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-39402"
    ],
    "name": "CVE-2026-39402",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-08T20:18:19Z",
    "bugzilla": {
      "description": "vim: Vim: Arbitrary code execution via command injection in NetBeans interface",
      "id": "2456722",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456722"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:N",
      "status": "draft"
    },
    "cwe": "CWE-78",
    "details": [
      "Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and specialKeys protocol messages. This vulnerability is fixed in 9.2.0316.",
      "A flaw was found in Vim. A command injection vulnerability in Vim's NetBeans interface allows a malicious NetBeans server to execute arbitrary Ex commands when Vim connects to it. This occurs due to unsanitized strings in the defineAnnoType and specialKeys protocol messages, leading to arbitrary code execution."
    ],
    "statement": "A command injection flaw in Vim's NetBeans interface allows a malicious NetBeans server to execute arbitrary commands when Vim connects to it. This happens because of Vim lacking the sanitization of strings in the protocol command messages, an attacker may leverage that to send maliciously crafted messages to the client that send a `|` character in certain command fields making Vim further interpret as an Ex command interpolation and executing arbitrary code in the victim's machine.\nRed Hat Product Security has rated this vulnerability as having the impact of Moderate, this happens because for an attack be considered successful the victim needs to deliberately connect to an untrusted malicious Netbeans server or the attacker needs to intercept the control messages and properly change it (MiTM) with the malicious payload. Additionally the code executed will be executed with the same privileges as the user running the Vim process, meaning the impact will be restricted by the same privilege level as the edit process has.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-39881\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-39881\nhttps://github.com/vim/vim/commit/7ab76a86048ed492374ac6b19\nhttps://github.com/vim/vim/releases/tag/v9.2.0316\nhttps://github.com/vim/vim/security/advisories/GHSA-mr87-rhgv-7pw6"
    ],
    "name": "CVE-2026-39881",
    "mitigation": {
      "value": "Users should refrain to connect to untrusted netbeans server.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-13T22:10:18Z",
    "bugzilla": {
      "description": "jq: missing runtime type checks for _strindices lead to crash and limited memory disclosure",
      "id": "2458076",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458076"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1287",
    "details": [
      "jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() checks that are stripped in release builds compiled with -DNDEBUG. This allows an attacker to crash jq trivially with input like _strindices(0), and by crafting a numeric value whose IEEE-754 bit pattern maps to a chosen pointer, achieve a controlled pointer dereference and limited memory read/probe primitive. Any deployment that evaluates untrusted jq filters against a release build is vulnerable. This issue has been patched in commit fdf8ef0f0810e3d365cdd5160de43db46f57ed03.",
      "A flaw was found in jq, a command line JSON processor. In release builds, the `_strindices` builtin function calls the `jv_string_indexes` function without checking that the arguments are actually strings. This missing validation allows an attacker who can supply non-string inputs to cause an application crash and a limited memory read."
    ],
    "statement": "To exploit this flaw, a user needs to process JSON input with an attacker-supplied argument to the `_strindices` builtin. This allows the attacker to cause an application crash and a limited memory read with no other security impact. Due to these reasons, this vulnerability has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8579",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.1-3.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-39956\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-39956\nhttps://github.com/jqlang/jq/commit/fdf8ef0f0810e3d365cdd5160de43db46f57ed03\nhttps://github.com/jqlang/jq/security/advisories/GHSA-6gc3-3g9p-xx28"
    ],
    "name": "CVE-2026-39956",
    "mitigation": {
      "value": "Do not use untrusted input as an argument to a jq builtin, specifically '_strindices'.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-13T22:18:56Z",
    "bugzilla": {
      "description": "jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers",
      "id": "2458077",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458077"
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.",
      "A flaw was found in jq, a command line JSON processor, specifically in the libjq API. Parsing a malformed JSON input from a non-NUL-terminated buffer using the `jv_parse_sized` function can cause an out-of-bounds read, resulting in an application crash and a possible memory disclosure within the error message generated by the parser."
    ],
    "statement": "To exploit this flaw, an attacker needs to supply malformed JSON from a non-NUL-terminated buffer to an application using the `jv_parse_sized` function. This allows the attacker to trigger the out-of-bounds read, causing an application crash and potentially disclosing memory with no other security impact. As this issue affects the libjq library, it is more likely to be exposed to untrusted input. Due to these reasons, this vulnerability has been rated with an important severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16692",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "jq-0:1.7.1-11.el10_1.0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19151",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "jq-0:1.7.1-11.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18040",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "jq-0:1.7.1-8.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16252",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "jq-0:1.6-12.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18048",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "jq-0:1.5-12.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18048",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "jq-0:1.5-12.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18047",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "jq-0:1.6-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18047",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "jq-0:1.6-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18047",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "jq-0:1.6-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18046",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "jq-0:1.6-6.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18046",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "jq-0:1.6-6.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16693",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "jq-0:1.6-19.el9_7.0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19365",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "jq-0:1.6-19.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18045",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "jq-0:1.6-12.el9_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18044",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "jq-0:1.6-15.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18043",
        "cpe": "cpe:/o:redhat:rhel_eus:9.4",
        "package": "jq-0:1.6-16.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18042",
        "cpe": "cpe:/o:redhat:rhel_eus:9.6",
        "package": "jq-0:1.6-17.el9_6.4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26528",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202606140301-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26542",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202606160406-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28887",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202606231112-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:23233",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202606030318-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-06-18T00:00:00Z",
        "advisory": "RHSA-2026:25044",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202606051757-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34098",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202606250942-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25181",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202606051320-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23245",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202606031700-0"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30078",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1782352950"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30087",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1782352919"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30088",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782353093"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30089",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1782352847"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8579",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.1-3.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-39979\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-39979\nhttps://github.com/jqlang/jq/commit/2f09060afab23fe9390cce7cb860b10416e1bf5f\nhttps://github.com/jqlang/jq/security/advisories/GHSA-2hhh-px8h-355p"
    ],
    "name": "CVE-2026-39979",
    "mitigation": {
      "value": "To mitigate this issue, manually ensure that every buffer is NUL-terminated before passing it to the 'jv_parse_sized' function.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-12T13:28:45Z",
    "bugzilla": {
      "description": "dovecot: Dovecot: Denial of Service due to Sieve script CPU limit bypass",
      "id": "2476470",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476470"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-770",
    "details": [
      "Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server performance and bypass configured CPU time limits for Sieve scripts. Install fixed version, or alternatively prevent direct access to Sieve scripts via ManageSieve or local access. No publicly available exploits are known.",
      "A flaw was found in Dovecot. A remote or local attacker could upload a malicious Sieve script through the ManageSieve service, or locally, to bypass configured CPU time limits for Sieve scripts. This allows the attacker to consume excessive server resources, leading to a degradation of server performance and a Denial of Service (DoS)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40016\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40016\nhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0002.json"
    ],
    "name": "CVE-2026-40016",
    "mitigation": {
      "value": "To mitigate this issue, restrict access to the ManageSieve service to trusted users or networks. If the ManageSieve service is not essential, consider disabling it. Additionally, ensure that local user access to Sieve script directories is appropriately controlled. Any changes to Dovecot configuration may require a service reload or restart, potentially causing a brief interruption to mail services.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-12T13:28:46Z",
    "bugzilla": {
      "description": "dovecot: dovecot: Denial of Service via IMAP SETACL command injection",
      "id": "2476465",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476465"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-88",
    "details": [
      "Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No publicly available exploits are known.",
      "A flaw was found in dovecot. A remote attacker can exploit the Internet Message Access Protocol (IMAP) SETACL command to inject \"anyone\" permissions into a user's dovecot-acl file, even when the imap_acl_allow_anyone setting is disabled. This vulnerability allows an attacker to spam folders to all users, leading to a denial of service by disrupting normal email service. No unauthorized access to user data is gained."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Out of support scope",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40020\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40020\nhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0002.json"
    ],
    "name": "CVE-2026-40020",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-13T23:40:12Z",
    "bugzilla": {
      "description": "jq: jq: Denial of Service via crafted JSON object causing hash collisions",
      "id": "2458084",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458084"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-341",
    "details": [
      "jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations, which allowed an attacker to precompute key collisions offline. By supplying a crafted JSON object (~100 KB) where all keys hashed to the same bucket, hash table lookups degraded from O(1) to O(n), turning any jq expression into an O(n²) operation and causing significant CPU exhaustion. This affected common jq use cases such as CI/CD pipelines, web services, and data processing scripts, and was far more practical to exploit than existing heap overflow issues since it required only a small payload. This issue has been patched in commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784.",
      "A flaw was found in jq, a command-line JSON processor. A remote attacker could exploit this vulnerability by providing a specially crafted JSON object. This object leverages a weakness in jq's hashing algorithm, which uses a hardcoded, publicly known seed. By crafting the JSON object to cause hash collisions, an attacker can degrade the performance of JSON object hash table operations, leading to significant CPU exhaustion and a denial of service (DoS) for systems processing the malicious JSON data."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16692",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "jq-0:1.7.1-11.el10_1.0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19151",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "jq-0:1.7.1-11.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18040",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "jq-0:1.7.1-8.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16252",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "jq-0:1.6-12.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18048",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "jq-0:1.5-12.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18048",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "jq-0:1.5-12.el8_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18047",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "jq-0:1.6-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18047",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "jq-0:1.6-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18047",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "jq-0:1.6-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18046",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "jq-0:1.6-6.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18046",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "jq-0:1.6-6.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16693",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "jq-0:1.6-19.el9_7.0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19365",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "jq-0:1.6-19.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18045",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "jq-0:1.6-12.el9_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18044",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "jq-0:1.6-15.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18043",
        "cpe": "cpe:/o:redhat:rhel_eus:9.4",
        "package": "jq-0:1.6-16.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18042",
        "cpe": "cpe:/o:redhat:rhel_eus:9.6",
        "package": "jq-0:1.6-17.el9_6.4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26528",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202606140301-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26542",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202606160406-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28887",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202606231112-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:23233",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202606030318-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-06-18T00:00:00Z",
        "advisory": "RHSA-2026:25044",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202606051757-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34098",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202606250942-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25181",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202606051320-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23245",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202606031700-0"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30078",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1782352950"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30087",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1782352919"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30088",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782353093"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30089",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1782352847"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8579",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.1-3.hum1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40164\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40164\nhttps://github.com/jqlang/jq/commit/0c7d133c3c7e37c00b6d46b658a02244fdd3c784\nhttps://github.com/jqlang/jq/security/advisories/GHSA-wwj8-gxm6-jc29"
    ],
    "name": "CVE-2026-40164",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-08T19:59:20Z",
    "bugzilla": {
      "description": "openvpn: OpenVPN: Server crash or memory leak due to race condition and use-after-free",
      "id": "2486561",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486561"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-364",
    "details": [
      "A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.",
      "A flaw was found in OpenVPN that occurs when a connection is being established or updated. A remote attacker could exploit this timing issue to crash the OpenVPN server, causing a temporary service disruption (Denial of Service). In some cases, it could also allow an attacker to view fragments of the server's temporary internal memory, potentially exposing sensitive data."
    ],
    "statement": "This Moderate impact flaw in OpenVPN is a race condition that can be remotely triggered during TLS session promotion. Successful exploitation could lead to a server crash, resulting in a denial of service, or potentially leak heap memory. The vulnerability's reliance on specific timing for the race condition to occur contributes to its Moderate severity.",
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40215\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40215\nhttps://community.openvpn.net/ReleaseHistory#openvpn-2620-released-22-april-2026\nhttps://community.openvpn.net/ReleaseHistory#openvpn-272-released-22-april-2026\nhttps://community.openvpn.net/Security%20Announcements/CVE-2026-40215"
    ],
    "name": "CVE-2026-40215",
    "mitigation": {
      "value": "To reduce the attack surface, restrict network access to the OpenVPN server to only trusted clients and networks. This can be achieved by configuring firewall rules to limit inbound connections to the OpenVPN port (default 1194/UDP or 443/TCP) from known, authorized sources. This operational control limits the ability of unauthorized remote attackers to attempt exploitation.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-10T15:16:19Z",
    "bugzilla": {
      "description": "systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output",
      "id": "2457324",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457324"
    },
    "cvss3": {
      "cvss3_base_score": "6.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-250",
    "details": [
      "In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.",
      "A flaw was found in udev in systemd. A local user with access to malicious hardware devices can exploit this vulnerability. By providing unsanitized kernel output, the flaw allows for local root execution, leading to privilege escalation."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7299",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "systemd-main-260.1-2.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rpm-ostree",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "NetworkManager",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "systemd",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40225\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40225\nhttps://github.com/systemd/systemd/security/advisories/GHSA-vpfq-8p5f-jcqx"
    ],
    "name": "CVE-2026-40225",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-10T15:18:10Z",
    "bugzilla": {
      "description": "systemd: systemd nspawn: Escape-to-host action via crafted config file",
      "id": "2457326",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457326"
    },
    "cvss3": {
      "cvss3_base_score": "6.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-348",
    "details": [
      "In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.",
      "A flaw was found in nspawn, a container runtime environment within systemd. A local attacker or a process within an nspawn container could exploit this vulnerability by using a specially crafted optional configuration file. This could allow the attacker to escape the container's isolation and execute arbitrary actions on the host system."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7299",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "systemd-main-260.1-2.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rpm-ostree",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "NetworkManager",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "systemd",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40226\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40226\nhttps://github.com/systemd/systemd/security/advisories/GHSA-9mj4-rrc3-gjcx"
    ],
    "name": "CVE-2026-40226",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-13T21:32:53Z",
    "bugzilla": {
      "description": "ImageMagick: Magick.NET: ImageMagick: Denial of service via heap out-of-bounds write in JP2 encoder",
      "id": "2458047",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458047"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-1285",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below both 7.1.2-19 and 6.9.13-44, contain a heap out-of-bounds write in the JP2 encoder with when a user specifies an invalid sampling index. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.",
      "A flaw was found in ImageMagick. This vulnerability, a heap out-of-bounds write, occurs within the JPEG 2000 (JP2) encoder when processing an image with an invalid sampling index. A remote attacker could exploit this by providing a specially crafted image, which may lead to a denial of service (DoS) by causing the application to crash or become unstable."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40310\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40310\nhttps://github.com/ImageMagick/ImageMagick/commit/3d653bea2df085c728a1c8f775808e1e9249dff9\nhttps://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pwg5-6jfc-crvh\nhttps://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"
    ],
    "name": "CVE-2026-40310",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-13T21:36:44Z",
    "bugzilla": {
      "description": "ImageMagick: Magick.NET: ImageMagick: Denial of Service via heap use-after-free in XMP profile processing",
      "id": "2458051",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458051"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 and 6.9.13-44 contain a heap use-after-free vulnerability that can cause a crash when reading and printing values from an invalid XMP profile. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.",
      "A flaw was found in ImageMagick. This heap use-after-free vulnerability can be triggered when processing an invalid XMP (Extensible Metadata Platform) profile. An attacker could craft a malicious image file that, when read and processed by ImageMagick, may lead to a crash, resulting in a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40311\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40311\nhttps://github.com/ImageMagick/ImageMagick/commit/5facfecf1abb3fed46a08f614dcc43d1e548e20d\nhttps://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r83h-crwp-3vm7\nhttps://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"
    ],
    "name": "CVE-2026-40311",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-17T23:11:11Z",
    "bugzilla": {
      "description": "libgphoto2: libgphoto2: Information disclosure and denial of service via unbounded reads",
      "id": "2459365",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459365"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-130",
    "details": [
      "libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2/ptp-pack.c accept a data pointer but no length parameter, performing unbounded reads. Their callers in ptp_unpack_EOS_events() have xsize available but never pass it, leaving both functions unable to validate reads against the actual buffer boundary. Commit 1817ecead20c2aafa7549dac9619fe38f47b2f53 patches the issue.",
      "A flaw was found in libgphoto2, a library used for camera access and control. Two functions within the library's Picture Transfer Protocol (PTP) handling component do not properly validate the size of data being read, allowing for unbounded reads. A local attacker with physical access to a system utilizing libgphoto2 could exploit this vulnerability. This could lead to the disclosure of sensitive information from memory or cause the application to crash, resulting in a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40333\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40333\nhttps://github.com/gphoto/libgphoto2/commit/1817ecead20c2aafa7549dac9619fe38f47b2f53\nhttps://github.com/gphoto/libgphoto2/security/advisories/GHSA-hq94-cp6h-3gjp"
    ],
    "name": "CVE-2026-40333",
    "mitigation": {
      "value": "To mitigate this vulnerability, restrict physical access to systems running libgphoto2. If camera access and control via libgphoto2 is not required, consider removing the `libgphoto2` package to eliminate the attack surface.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-17T23:16:38Z",
    "bugzilla": {
      "description": "libgphoto2: libgphoto2: Information disclosure and denial of service via missing null terminator",
      "id": "2459356",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459356"
    },
    "cvss3": {
      "cvss3_base_score": "3.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-170",
    "details": [
      "libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, a missing null terminator exists in ptp_unpack_Canon_FE() in camlibs/ptp2/ptp-pack.c (line 1377). The function copies a filename into a 13-byte buffer using strncpy without explicitly null-terminating the result. If the source data is exactly 13 bytes with no null terminator, the buffer is left unterminated, leading to out-of-bounds reads in any subsequent string operation. Commit 259fc7d3bfe534ce4b114c464f55b448670ab873 patches the issue.",
      "A flaw was found in libgphoto2, a camera access and control library. A missing null terminator in the `ptp_unpack_Canon_FE()` function, when processing a specially crafted 13-byte filename, can lead to an out-of-bounds read. This vulnerability may allow a local attacker with physical access to cause information disclosure or a denial of service (DoS)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40334\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40334\nhttps://github.com/gphoto/libgphoto2/commit/259fc7d3bfe534ce4b114c464f55b448670ab873\nhttps://github.com/gphoto/libgphoto2/security/advisories/GHSA-ph87-cc3j-c6hm"
    ],
    "name": "CVE-2026-40334",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-17T23:19:16Z",
    "bugzilla": {
      "description": "libgphoto2: libgphoto2: Information disclosure via out-of-bounds read in ptp_unpack_DPV()",
      "id": "2459354",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459354"
    },
    "cvss3": {
      "cvss3_base_score": "5.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_DPV()` in `camlibs/ptp2/ptp-pack.c` (lines 622–629). The UINT128 and INT128 cases advance `*offset += 16` without verifying that 16 bytes remain in the buffer. The entry check at line 609 only guarantees `*offset < total` (at least 1 byte available), leaving up to 15 bytes unvalidated. Commit 433bde9888d70aa726e32744cd751d7dbe94379a patches the issue.",
      "A flaw was found in libgphoto2, a library for camera access. This out-of-bounds read vulnerability in the `ptp_unpack_DPV()` function occurs because the software does not properly validate buffer boundaries when handling specific data types. An attacker with physical access to the device could exploit this to potentially disclose sensitive information or cause a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40335\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40335\nhttps://github.com/gphoto/libgphoto2/commit/433bde9888d70aa726e32744cd751d7dbe94379a\nhttps://github.com/gphoto/libgphoto2/security/advisories/GHSA-g4g5-c2x9-cqfj"
    ],
    "name": "CVE-2026-40335",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-17T23:27:42Z",
    "bugzilla": {
      "description": "libgphoto2: libgphoto2: Memory leak in ptp_unpack_Sony_DPD() can lead to denial of service",
      "id": "2459370",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459370"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-772",
    "details": [
      "libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have a memory leak in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (lines 884–885). When processing a secondary enumeration list (introduced in 2024+ Sony cameras), the function overwrites dpd->FORM.Enum.SupportedValue with a new calloc() without freeing the previous allocation from line 857. The original array and any string values it contains are leaked on every property descriptor parse. Commit 404ff02c75f3cb280196fc260a63c4d26cf1a8f6 fixes the issue.",
      "A flaw was found in libgphoto2, a camera access and control library. When processing a secondary enumeration list from certain Sony cameras, the `ptp_unpack_Sony_DPD()` function improperly handles memory allocation. This oversight causes a memory leak, which can lead to resource exhaustion and potentially result in a Denial of Service (DoS) for applications utilizing the library."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Under investigation",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Under investigation",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40336\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40336\nhttps://github.com/gphoto/libgphoto2/commit/404ff02c75f3cb280196fc260a63c4d26cf1a8f6\nhttps://github.com/gphoto/libgphoto2/security/advisories/GHSA-g8xw-p5wj-mrxv"
    ],
    "name": "CVE-2026-40336",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-17T23:40:10Z",
    "bugzilla": {
      "description": "libgphoto2: libgphoto2: Information disclosure and denial of service via out-of-bounds read",
      "id": "2459368",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459368"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the PTP_DPFF_Enumeration case of `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 856). The function reads a 2-byte enumeration count N via `dtoh16o(data, *poffset)` without verifying that 2 bytes remain in the buffer. The standard `ptp_unpack_DPD()` at line 704 has this exact check, confirming the Sony variant omitted it by oversight. Commit 3b9f9696be76ae51dca983d9dd8ce586a2561845 fixes the issue.",
      "A flaw was found in libgphoto2, a library for camera access and control. An out-of-bounds read vulnerability exists in the `ptp_unpack_Sony_DPD()` function. This occurs when the function attempts to read a 2-byte enumeration count without first verifying that sufficient data remains in the buffer. A local attacker or a malicious device connected to the system could exploit this to potentially disclose sensitive information from memory or cause a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40338\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40338\nhttps://github.com/gphoto/libgphoto2/commit/3b9f9696be76ae51dca983d9dd8ce586a2561845\nhttps://github.com/gphoto/libgphoto2/security/advisories/GHSA-2hwp-w84q-27hf"
    ],
    "name": "CVE-2026-40338",
    "mitigation": {
      "value": "To mitigate this issue, restrict physical access to systems running libgphoto2 and avoid connecting untrusted or malicious devices. This operational control limits the attack surface by preventing the necessary physical interaction or device connection required for exploitation.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-17T23:42:32Z",
    "bugzilla": {
      "description": "libgphoto2: libgphoto2: Information Disclosure via out-of-bounds read",
      "id": "2459357",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459357"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 842). The function reads the FormFlag byte via `dtoh8o(data, *poffset)` without a prior bounds check. The standard `ptp_unpack_DPD()` at lines 686–687 correctly validates `*offset + sizeof(uint8_t) > dpdlen` before this same read, but the Sony variant omits this check entirely. Commit 09f8a940b1e418b5693f5c11e3016a1ad2cea62d fixes the issue.",
      "A flaw was found in libgphoto2, a library for camera access and control. An out-of-bounds read vulnerability exists in the `ptp_unpack_Sony_DPD()` function due to a missing bounds check when reading the FormFlag byte. This flaw could allow an attacker to disclose sensitive information from memory."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40339\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40339\nhttps://github.com/gphoto/libgphoto2/commit/09f8a940b1e418b5693f5c11e3016a1ad2cea62d\nhttps://github.com/gphoto/libgphoto2/security/advisories/GHSA-42cm-m9hc-r7q8"
    ],
    "name": "CVE-2026-40339",
    "mitigation": {
      "value": "If camera interaction is not required, remove the `libgphoto2` package to eliminate this vulnerability. Alternatively, avoid connecting untrusted cameras or processing untrusted image data through applications that utilize `libgphoto2`. This operational control reduces exposure by limiting the attack surface.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-17T23:45:17Z",
    "bugzilla": {
      "description": "libgphoto2: libgphoto2: Information disclosure and denial of service via out-of-bounds read",
      "id": "2459367",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459367"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulnerability in `ptp_unpack_OI()` in `camlibs/ptp2/ptp-pack.c` (lines 530–563). The function validates `len < PTP_oi_SequenceNumber` (i.e., len < 48) but subsequently accesses offsets 48–56, up to 9 bytes beyond the validated boundary, via the Samsung Galaxy 64-bit objectsize detection heuristic. Commit 7c7f515bc88c3d0c4098ac965d313518e0ccbe33 fixes the issue.",
      "A flaw was found in libgphoto2, a library for camera access and control. An out-of-bounds read vulnerability exists in the `ptp_unpack_OI()` function due to insufficient validation. A local attacker could exploit this by crafting specific input related to the Samsung Galaxy 64-bit objectsize detection heuristic. This could lead to information disclosure or a denial of service by causing the application to crash."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40340\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40340\nhttps://github.com/gphoto/libgphoto2/commit/7c7f515bc88c3d0c4098ac965d313518e0ccbe33\nhttps://github.com/gphoto/libgphoto2/security/advisories/GHSA-xfw3-xvjp-5wcv"
    ],
    "name": "CVE-2026-40340",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-17T23:48:36Z",
    "bugzilla": {
      "description": "libgphoto2: libgphoto2: Denial of Service via out-of-bounds read from untrusted USB devices",
      "id": "2459358",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459358"
    },
    "cvss3": {
      "cvss3_base_score": "4.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB devices. Commit c385b34af260595dfbb5f9329526be5158985987 contains a patch. No known workarounds are available.",
      "A flaw was found in libgphoto2, a library used for accessing and controlling cameras. An out-of-bounds read vulnerability exists in the ptp_unpack_EOS_FocusInfoEx function. This flaw can be exploited by processing input from untrusted USB devices, potentially allowing an attacker to crash the libgphoto2 application. This leads to a denial of service (DoS) for users."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libgphoto2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40341\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40341\nhttps://github.com/gphoto/libgphoto2/commit/c385b34af260595dfbb5f9329526be5158985987\nhttps://github.com/gphoto/libgphoto2/security/advisories/GHSA-vjx3-gjp6-r2g2"
    ],
    "name": "CVE-2026-40341",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Critical",
    "public_date": "2026-04-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "9.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library's initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server's OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40342\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40342"
    ],
    "name": "CVE-2026-40342",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-28T00:00:00Z",
    "bugzilla": {
      "description": "krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism",
      "id": "2463370",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2463370"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
      "A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit a NULL pointer dereference vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the termination of the process, resulting in a Denial of Service (DoS)."
    ],
    "statement": "Moderate: This flaw allows an unauthenticated remote attacker to cause a Denial of Service in MIT Kerberos 5 by triggering a NULL pointer dereference. Exploitation requires the NegoEx mechanism to be explicitly registered in the system's GSSAPI configuration, which is not a default state in all Red Hat environments.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19145",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "krb5-0:1.21.3-10.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16799",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "krb5-0:1.18.2-34.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19357",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "krb5-0:1.21.1-10.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19357",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "krb5-0:1.21.1-10.el9_8"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12220",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "krb5-main-1.22.2-7.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22634",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1780420428"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1779798159"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1779798164"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "krb5",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "krb5",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40355\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40355\nhttps://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html\nhttps://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f\nhttps://web.mit.edu/kerberos/advisories/"
    ],
    "name": "CVE-2026-40355",
    "mitigation": {
      "value": "To mitigate this issue, remove the NegoEx mechanism registration from the system's GSSAPI configuration if it is not required. This can typically be achieved by removing or commenting out the relevant entry in `/etc/gss/mech`. A restart of services utilizing Kerberos might be necessary for the changes to take effect, which could impact Kerberos-dependent functionality.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-28T00:00:00Z",
    "bugzilla": {
      "description": "krb5: MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read",
      "id": "2463368",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2463368"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-191",
    "details": [
      "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
      "A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit an integer underflow and an out-of-bounds read vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the process terminating, resulting in a Denial of Service (DoS)."
    ],
    "statement": "This Moderate impact denial of service flaw in MIT Kerberos 5 (krb5) allows an unauthenticated remote attacker to trigger an integer underflow and out-of-bounds read. This vulnerability, which can lead to process termination, specifically affects systems where the NegoEx mechanism is registered and `gss_accept_sec_context()` is called. While Kerberos is a fundamental service, the prerequisite of a registered NegoEx mechanism limits the attack surface.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19145",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "krb5-0:1.21.3-10.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:16799",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "krb5-0:1.18.2-34.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19357",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "krb5-0:1.21.1-10.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19357",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "krb5-0:1.21.1-10.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-09T00:00:00Z",
        "advisory": "RHSA-2026:24685",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "krb5-0:1.20.1-9.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-09T00:00:00Z",
        "advisory": "RHSA-2026:24686",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "krb5-0:1.21.1-2.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-09T00:00:00Z",
        "advisory": "RHSA-2026:24683",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "krb5-0:1.21.1-8.el9_6.2"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.6",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43692",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.6::el9",
        "package": "oadp/oadp-velero-rhel9:1784058822"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12220",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "krb5-main-1.22.2-7.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22634",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1780420428"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1779798159"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1779798164"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "krb5",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "krb5",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40356\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40356\nhttps://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html\nhttps://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f\nhttps://web.mit.edu/kerberos/advisories/"
    ],
    "name": "CVE-2026-40356",
    "mitigation": {
      "value": "To mitigate this issue, ensure that the NegoEx mechanism is not registered in the `/etc/gss/mech` configuration file. Removing the corresponding entry from this file will prevent the vulnerable code path from being activated. This action may impact services that rely on the NegoEx GSS-API mechanism. A restart of affected Kerberos-dependent services may be required for the change to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-13T12:07:52Z",
    "bugzilla": {
      "description": "gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c",
      "id": "2499658",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499658"
    },
    "cvss3": {
      "cvss3_base_score": "4.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "Use After Free vulnerability has been found in \"io.c\" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.",
      "A flaw was found in gawk. A Use After Free vulnerability exists in the do_getline_redir() routine within the io.c program file. This vulnerability can be triggered by an attacker, potentially leading to a system crash and causing a Denial of Service (DoS)."
    ],
    "statement": "Moderate: A Use After Free vulnerability in gawk's `do_getline_redir()` routine can lead to a denial of service. This flaw, affecting gawk in Red Hat Hardened Images, requires a local attacker with low privileges to trick a user into interacting with specially crafted input, limiting its immediate impact.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:40041",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gawk-main-5.4.0-3.1.hum1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49661",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gawk-main-5.4.1-1.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40467\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40467\nhttps://cert.pl/en/posts/2026/07/CVE-2026-40467\nhttps://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8"
    ],
    "name": "CVE-2026-40467",
    "mitigation": {
      "value": "To mitigate this issue, users should avoid processing untrusted or maliciously crafted input with `gawk`. Exercise caution when executing `gawk` scripts or commands that process data from unknown or unverified sources.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-13T12:07:54Z",
    "bugzilla": {
      "description": "gawk: gawk: Memory corruption via integer overflow",
      "id": "2499655",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499655"
    },
    "cvss3": {
      "cvss3_base_score": "4.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "Integer overflow vulnerability has been found in \"builtin.c\" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.",
      "A flaw was found in gawk. An integer overflow vulnerability could allow a local attacker to cause memory exhaustion, leading to a denial of service. This flaw may also enable an attacker to corrupt gawk's internal memory, potentially leading to system instability."
    ],
    "statement": "Moderate: An integer overflow vulnerability in gawk's builtin.c could allow a local attacker to cause memory exhaustion and overwrite heap metadata. This could lead to system instability or a denial of service on affected Red Hat products, requiring local access to execute a malicious gawk script.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:40041",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gawk-main-5.4.0-3.1.hum1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49661",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gawk-main-5.4.1-1.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40468\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40468\nhttps://cert.pl/en/posts/2026/07/CVE-2026-40467\nhttps://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7"
    ],
    "name": "CVE-2026-40468",
    "mitigation": {
      "value": "Do not execute untrusted awk scripts or process untrusted inputs that could trigger oversized calculations in builtin.c.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-13T12:07:56Z",
    "bugzilla": {
      "description": "gawk: Gawk: Buffer overflow in ftype() routine may lead to code execution or denial of service",
      "id": "2499657",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499657"
    },
    "cvss3": {
      "cvss3_base_score": "6.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-121",
    "details": [
      "Buffer overflow vulnerability has been found in \"extension/readdir.c\" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.",
      "A flaw was found in gawk. A buffer overflow vulnerability exists in the `ftype()` routine, located in the `extension/readdir.c` program file. This vulnerability could allow an attacker to crash the program, resulting in a denial of service. It may also potentially lead to arbitrary code execution, though this has not been definitively confirmed."
    ],
    "statement": "Moderate: A buffer overflow in gawk's `ftype()` routine, when processing untrusted input, could lead to a denial of service or potentially arbitrary code execution. This is rated Moderate as successful exploitation requires user interaction, such as processing a specially crafted file.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:40041",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gawk-main-5.4.0-3.1.hum1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49661",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gawk-main-5.4.1-1.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "gawk",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40553\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40553\nhttps://cert.pl/en/posts/2026/07/CVE-2026-40467\nhttps://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843"
    ],
    "name": "CVE-2026-40553",
    "mitigation": {
      "value": "Do not run gawk against untrusted scripts, files, or directories to prevent triggering these vulnerabilities. If an attack is attempted, Red Hat's built-in memory protections will safely crash the program, preventing malicious code execution.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-11T17:16:25Z",
    "bugzilla": {
      "description": "jq: stack overflow via unbounded recursion in jv_contains",
      "id": "2469183",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2469183"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-674",
    "details": [
      "jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.",
      "A flaw was found in jq, a command line JSON processor. The `jv_contains` function does not have a depth limit when processing nested arrays or objects. This missing depth limit allows an attacker who can supply a sufficiently nested input structure to exhaust the stack memory, causing an application crash and resulting in a denial of service."
    ],
    "statement": "To exploit this issue, an attacker needs to supply a crafted JSON input to be processed by jq with the `jv_contains` function. This allows the attacker to cause an application crash with no other security impact. Due to these reasons, this vulnerability has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29986",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40612\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40612\nhttps://github.com/jqlang/jq/security/advisories/GHSA-r7m6-x9c7-h69j"
    ],
    "name": "CVE-2026-40612",
    "mitigation": {
      "value": "Do not process untrusted input with the jq command line JSON processor.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-13T14:12:43Z",
    "bugzilla": {
      "description": "nginx: ngx_http_ssl_module: data corruption and denial of service",
      "id": "2477076",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477076"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "status": "draft"
    },
    "cwe": "CWE-416",
    "details": [
      "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to \"on\" or \"optional,\" and the ssl_ocsp directive is set to \"on\" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.\n Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in the ngx_http_ssl_module module of NGINX. When the ssl_verify_client directive is set to \"on\" or \"optional\" and the ssl_ocsp directive is enabled or its leaf parameters are configured with a resolver, an unauthenticated attacker can send crafted requests to cause a use-after-free issue in the worker process, resulting in a limited modification of memory data or a denial of service by forcing the process to restart."
    ],
    "statement": "To exploit this flaw, the ssl_verify_client directive must be set to \"on\" or \"optional\" and the ssl_ocsp directive must be enabled or its leaf parameters configured with a resolver, limiting its exposure as this is not the default configuration. This issue allows an attacker to have limited control to modify memory data from the worker process or cause a denial of service by forcing the process to restart, but it cannot cause a complete system denial of service. Due to these reasons, this flaw has been rated with a moderate severity.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nginx:1.24/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "nginx:1.24/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nginx:1.26/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "nginx",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Lightspeed proxy 1",
        "fix_state": "Fix deferred",
        "package_name": "insights-proxy/insights-proxy-container-rhel9",
        "cpe": "cpe:/a:redhat:insights_proxy:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40701\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40701\nhttps://my.f5.com/manage/s/article/K000161021"
    ],
    "name": "CVE-2026-40701",
    "mitigation": {
      "value": "To mitigate this issue, specifically set the OCSP responder using the ssl_ocsp_responder directive or switch from live OCSP validation to static CRL files using the ssl_crl directive. If neither configuration is possible, using a local DNS server to cache and quickly resolve OCSP responder names can reduce the probability of exploitation.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A heap buffer overflow exists in ntfs_build_permissions_posix() (acls.c:4011-4027) that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs.\n\nThe overflow size is attacker-controlled (8 to 14,000+ bytes) and writes partially attacker-controlled data (POSIX_ACE entries with attacker-derived GID values) past the heap allocation. This corrupts adjacent glibc heap chunk metadata, as confirmed by a crash in _int_free() with \"free(): corrupted unsorted chunks\"."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-40706\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-40706"
    ],
    "name": "CVE-2026-40706",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-13T00:00:00Z",
    "bugzilla": {
      "description": "systemd: systemd: Privilege escalation via improper access control in RegisterMachine D-Bus method",
      "id": "2447262",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447262"
    },
    "cvss3": {
      "cvss3_base_score": "6.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-284",
    "details": [
      "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
      "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."
    ],
    "statement": "The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate. The issue allows a local privilege escalation to root through the systemd-machined service when specific environmental conditions are met. Successful exploitation requires an unprivileged user to be logged into an active graphical desktop session on a system where systemd-machined is present. Additionally, the affected component is not typically installed by default on many systems and terminal-only or remote sessions (such as SSH) are not affected.",
    "acknowledgement": "Red Hat would like to thank Asim Viladi Oglu Manizada for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7299",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "systemd-main-260.1-2.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rpm-ostree",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "systemd",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "NetworkManager",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "systemd",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4105\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4105\nhttps://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"
    ],
    "name": "CVE-2026-4105",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-24T16:45:19Z",
    "bugzilla": {
      "description": "lxml: python: lxml: Information disclosure via untrusted XML input leading to local file read",
      "id": "2461613",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461613"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-611",
    "details": [
      "lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0.",
      "A flaw was found in lxml, a library for processing XML and HTML in Python. A remote attacker can exploit this vulnerability by sending untrusted XML input to an application using lxml's default parser configuration. This allows the attacker to read local files on the system, leading to information disclosure."
    ],
    "package_state": [
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Fix deferred",
        "package_name": "mta/mta-solution-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:0"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python-lxml",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "python-lxml",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python-lxml",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python-lxml",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python-lxml",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "abattis-cantarell-fonts",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "mariadb11.8",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python3-mypy",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-jsonschema",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-referencing",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ta-lmes-job-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-olm-catalogd-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "python-lxml",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite:el8/python-lxml",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Update Infrastructure 4 for Cloud Providers",
        "fix_state": "Fix deferred",
        "package_name": "python-lxml",
        "cpe": "cpe:/a:redhat:rhui:4::el8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-41066\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41066\nhttps://bugs.launchpad.net/lxml/+bug/2146291\nhttps://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw"
    ],
    "name": "CVE-2026-41066",
    "mitigation": {
      "value": "Applications using the lxml library to process untrusted XML input should explicitly configure the parser to prevent external entity resolution. This can be achieved by setting the `resolve_entities` option to `False` or `'internal'` when initializing the parser. For example, `etree.XML(xml_input, parser=etree.XMLParser(resolve_entities=False))` or `etree.HTML(html_input, parser=etree.HTMLParser(resolve_entities='internal'))`.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-24T16:54:38Z",
    "bugzilla": {
      "description": "cups: CUPS: Information disclosure via crafted SNMP response",
      "id": "2461611",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461611"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17.",
      "A flaw was found in CUPS. A network-adjacent attacker can send a specially crafted Simple Network Management Protocol (SNMP) response to the CUPS SNMP backend, leading to an out-of-bounds read. This vulnerability allows for the disclosure of up to 176 bytes of sensitive memory, which is then converted and stored as printer supply description strings. Authenticated users can subsequently view this leaked information through IPP Get-Printer-Attributes responses and the CUPS web interface."
    ],
    "statement": "This is a Low impact information disclosure flaw in CUPS, where a network-adjacent attacker can trigger an out-of-bounds read in the SNMP backend. This vulnerability allows for the disclosure of up to 176 bytes of sensitive memory, which is then accessible to authenticated users via the CUPS web interface or IPP responses. The impact is limited due to the network-adjacent attack vector, the requirement for authenticated access to view the leaked data and the small amount of leak information which is then garbled by the UTF-8 conversion. For the CUPS versions distributed with Red Hat supported products there's no availability impact as CUPS is not built with debugging mechanisms, such as address sanitizers or valgrind, which could lead the targeted application to crash.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "cups",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "cups",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-41079\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41079\nhttps://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080\nhttps://github.com/OpenPrinting/cups/commit/d7fe0f521ff3b24676511e747b058362b9a20737\nhttps://github.com/OpenPrinting/cups/security/advisories/GHSA-6wpw-g8g6-wvrv"
    ],
    "name": "CVE-2026-41079",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-16T16:52:01Z",
    "bugzilla": {
      "description": "libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML",
      "id": "2458967",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458967"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-331",
    "details": [
      "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
      "A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing a specially crafted XML document that leverages insufficient entropy in the hash function. This can lead to hash flooding, a type of Denial of Service (DoS) attack, where the system becomes unresponsive or crashes due to excessive resource consumption."
    ],
    "statement": "This Low impact denial of service flaw in libexpat could allow a remote attacker to cause the program consuming libexpat to become unresponsive or crash. This vulnerability requires the processing of a specially crafted XML document, which could lead to excessive resource consumption due to hash flooding.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:11004",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "expat-main-2.8.0-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "compat-expat1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-41080\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41080\nhttps://github.com/libexpat/libexpat/issues/47\nhttps://github.com/libexpat/libexpat/pull/1183"
    ],
    "name": "CVE-2026-41080",
    "mitigation": {
      "value": "Applications that process untrusted XML documents using libexpat should implement robust input validation to filter out malicious XML structures. Restricting access to services that process untrusted XML can also reduce the attack surface. If a service is affected, restarting it may be required after implementing input validation or access restrictions.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-11T00:00:00Z",
    "bugzilla": {
      "description": "libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive",
      "id": "2446453",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446453"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-835",
    "details": [
      "A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.",
      "A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives."
    ],
    "statement": "The Red Hat Product Security team would likely assess the severity of this vulnerability as High because it allows remote attackers to cause a persistent denial-of-service condition using a small crafted archive file. Successful exploitation requires no authentication, no special configuration, and no user interaction in environments that automatically process uploaded archives. By repeatedly submitting malicious archives, an attacker can exhaust CPU resources or worker threads in services such as file upload systems, CI/CD pipelines, mail scanners, and content indexing services that rely on libarchive for archive extraction.",
    "acknowledgement": "Red Hat would like to thank Elhanan Haenel for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5063",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "libarchive-0:3.7.7-5.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8865",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libarchive-0:3.7.7-5.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5080",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libarchive-0:3.5.3-7.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-03-19T00:00:00Z",
        "advisory": "RHSA-2026:5080",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libarchive-0:3.5.3-7.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7093",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "libarchive-0:3.5.3-2.el9_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-06T00:00:00Z",
        "advisory": "RHSA-2026:6647",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libarchive-0:3.5.3-5.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7106",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "libarchive-0:3.5.3-4.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-08T00:00:00Z",
        "advisory": "RHSA-2026:7105",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libarchive-0:3.5.3-6.el9_6.1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:7239",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202604080111-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:15087",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202605060243-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14773",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202605060220-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10097",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202604211449-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17596",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202605112123-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:8423",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202604140044-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:10081",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202604211219-0"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7335",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1775740563"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16008",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1778244559"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16009",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1778244531"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8746",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1775680192"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8747",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1775680262"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-04-17T00:00:00Z",
        "advisory": "RHSA-2026:8748",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1775749857"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7329",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1775668717"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-04-09T00:00:00Z",
        "advisory": "RHSA-2026:7329",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1775675922"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8944",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libarchive-main-3.8.7-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9832",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1776868961"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1776868774"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1776868744"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1776868772"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4111\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4111\nhttps://github.com/libarchive/libarchive/pull/2877"
    ],
    "name": "CVE-2026-4111",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-11T17:18:30Z",
    "bugzilla": {
      "description": "jq: embedded NUL truncates top-level jq programs loaded with -f",
      "id": "2469193",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2469193"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-158",
    "details": [
      "jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.",
      "A flaw was found in jq, a command line JSON processor. Top-level jq programs loaded from a file using the `-f` flag are truncated at the first embedded NUL byte. This issue allows an attacker who can supply a crafted filter file to prematurely truncate the program, potentially bypassing filtering logic and modifying the integrity of the processed data."
    ],
    "statement": "To exploit this flaw, an attacker needs to supply a crafted filter file containing an embedded NUL byte to be loaded by jq using the `-f` flag. This allows the attacker to prematurely truncate the program, potentially bypassing intended filtering logic and modifying the integrity of the processed data. Due to these reasons, this issue has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29986",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-41256\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41256\nhttps://github.com/jqlang/jq/security/advisories/GHSA-vf2h-chrj-q3fg"
    ],
    "name": "CVE-2026-41256",
    "mitigation": {
      "value": "Do not process untrusted filter files using the -f flag with the jq command line JSON processor.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-11T17:14:32Z",
    "bugzilla": {
      "description": "jq: signed-int overflow in stack_reallocate",
      "id": "2469187",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2469187"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.",
      "A flaw was found in jq, a command line JSON processor. The memory allocation size is calculated using a signed integer that can overflow when processing deeply nested generator forks. This integer overflow allows an attacker who can supply a sufficiently nested input to influence the memory allocation size, causing an out-of-bounds write and an application crash, resulting in a denial of service."
    ],
    "statement": "To exploit this issue, an attacker needs to supply a crafted JSON input to be processed by jq that triggers deeply nested generator forks. This allows the attacker to overflow the integer used to calculate memory size and cause an out-of-bounds write, effectively resulting in an application crash with no other security impact. Due to these reasons, this vulnerability has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29986",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-41257\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41257\nhttps://github.com/jqlang/jq/security/advisories/GHSA-4jm8-m363-4539"
    ],
    "name": "CVE-2026-41257",
    "mitigation": {
      "value": "Do not process untrusted input with the jq command line JSON processor.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-12T15:14:45Z",
    "bugzilla": {
      "description": "tomcat: Apache Tomcat: Denial of Service due to uncontrolled resource allocation",
      "id": "2476518",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476518"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117.\nOlder, unsupported versions may also be affected.\nUsers are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.",
      "In Apache Tomcat, no limit was enforced on the request body for WebDAV LOCK or PROPFIND requests which were available to unauthenticated users. This allows a remote attacker to consume excessive resources, leading to Denial of Service (DoS), making the affected system unavailable to legitimate users."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat JBoss Web Server 6.2.4",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43402",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2",
        "package": "tomcat-catalina"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 10",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 8",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el9jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0.0",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39189",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
        "package": "tomcat-catalina"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 10",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 8",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 9",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el9jws"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat build of Apache Camel - HawtIO 4",
        "fix_state": "Affected",
        "package_name": "tomcat-embed-core",
        "cpe": "cpe:/a:redhat:apache_camel_hawtio:4"
      },
      {
        "product_name": "Red Hat build of Debezium 3",
        "fix_state": "Will not fix",
        "package_name": "annotations-api",
        "cpe": "cpe:/a:redhat:debezium:3"
      },
      {
        "product_name": "Red Hat Data Grid 8",
        "fix_state": "Not affected",
        "package_name": "tomcat-embed-core",
        "cpe": "cpe:/a:redhat:jboss_data_grid:8"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Will not fix",
        "package_name": "tomcat-embed-core",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat Single Sign-On 7",
        "fix_state": "Fix deferred",
        "package_name": "tomcat-embed-core",
        "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-41284\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41284\nhttps://lists.apache.org/thread/2nvqjr7ovjmvx2vbhb7s61ycd5msc8qc"
    ],
    "name": "CVE-2026-41284",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-12T15:19:35Z",
    "bugzilla": {
      "description": "tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated",
      "id": "2476513",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476513"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-1286",
    "details": [
      "Improper Input Validation vulnerability in Apache Tomcat.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27.\nOlder, end of support versions may also be affected.\nUsers are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.",
      "Apache Tomcat did not validate HTTP/2 request headers, triggering unexpected application behavior, as applications may presume that header values exposed through the Servlet API would be valid."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat JBoss Web Server 6.2.4",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43402",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2",
        "package": "tomcat-coyote"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 10",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 8",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el9jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0.0",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39189",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
        "package": "tomcat-coyote"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 10",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 8",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 9",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el9jws"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "tomcat10",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "tomcat11",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Under investigation",
        "package_name": "jws5-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-41293\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41293\nhttps://lists.apache.org/thread/qwg0q16z7xkb2qrr853wdll5531mvl1r"
    ],
    "name": "CVE-2026-41293",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-24T02:35:41Z",
    "bugzilla": {
      "description": "erb: ERB: Arbitrary code execution via deserialization bypass",
      "id": "2461369",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461369"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-502",
    "details": [
      "ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.",
      "A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18065",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "ruby-0:3.3.10-12.el10_1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20606",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "ruby4.0-0:4.0.3-34.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33478",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "ruby-0:3.3.10-11.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20614",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "ruby:3.3-8100020260428163940.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18030",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "ruby:3.3-9070020260428163621.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18039",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "ruby-0:3.0.7-166.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20596",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "ruby:4.0-9080020260513131334.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20670",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "ruby-0:3.0.4-160.2.el9_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35834",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "ruby-0:3.0.4-161.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26312",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "ruby-0:3.0.7-162.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26655",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "ruby:3.3-9040020260520083544.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33462",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "ruby-0:3.0.7-165.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37238",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "ruby:3.3-9060020260630075016.9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "ruby:2.5/ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "ruby3.3",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "ruby3.4",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "ruby4.0",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-41316\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41316\nhttps://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv"
    ],
    "name": "CVE-2026-41316",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-27T09:20:12Z",
    "bugzilla": {
      "description": "Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix",
      "id": "2463175",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2463175"
    },
    "cvss3": {
      "cvss3_base_score": "9.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-502",
    "details": [
      "The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.\nAffected versions are Apache MINA 2.0.0 <= 2.0.27, 2.1.0 <= 2.1.10, and 2.2.0 <= 2.2.5.\nThe problem is resolved in Apache MINA 2.0.28, 2.1.11, and 2.2.6 by \napplying the classname allowlist earlier.\nAffected are applications using Apache MINA that call IoBuffer.getObject().\nApplications using Apache MINA are advised to upgrade",
      "A flaw was found in Apache MINA. An incomplete fix for a deserialization vulnerability in the `AbstractIoBuffer.getObject()` method allowed a static initializer in a class to be executed before the classname allowlist was applied. This could enable a remote attacker to execute arbitrary code by sending specially crafted data to an application using Apache MINA that calls `IoBuffer.getObject()`."
    ],
    "statement": "Red Hat products are affected by this vulnerability. However, the vulnerable code cannot be reached and therefore are not vulnerable. Due to this reason, this flaw has been rated with a low severity.",
    "package_state": [
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "jenkins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "jenkins-2-plugins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "Red Hat AMQ Broker 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:amq_broker:7"
      },
      {
        "product_name": "Red Hat build of Apache Camel for Spring Boot 4",
        "fix_state": "Fix deferred",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:camel_spring_boot:4"
      },
      {
        "product_name": "Red Hat Data Grid 8",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_data_grid:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "javapackages-tools:201801/maven-wagon",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "maven:3.9/maven-wagon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "maven-wagon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Fuse 7",
        "fix_state": "Fix deferred",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_fuse:7"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform 8",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jbosseapxp"
      },
      {
        "product_name": "Red Hat Process Automation 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
      },
      {
        "product_name": "Red Hat Single Sign-On 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
      },
      {
        "product_name": "streams for Apache Kafka 2",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:amq_streams:2"
      },
      {
        "product_name": "streams for Apache Kafka 3",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:amq_streams:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-41409\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41409\nhttps://lists.apache.org/thread/9ddvsq6c4l5bhwq8l14sob4f8qjvx5c9"
    ],
    "name": "CVE-2026-41409",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-24T16:51:39Z",
    "bugzilla": {
      "description": "vim: Vim: Command injection allows arbitrary code execution via malicious tag files",
      "id": "2461614",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461614"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-78",
    "details": [
      "Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `command`), Vim executes the embedded command via the system shell with the full privileges of the running user.",
      "A flaw was found in Vim, an open-source command-line text editor. This command injection vulnerability occurs during tag file processing. A local user could craft a malicious tags file containing backtick syntax in the filename field. When Vim resolves a tag from this file, it executes the embedded command via the system shell, leading to arbitrary code execution with the privileges of the running user."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28210",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "vim-2:9.1.083-9.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30900",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28553",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-24.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28553",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-24.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33453",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33453",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34477",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34477",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34476",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34476",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28209",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28209",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28133",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "vim-2:8.2.2637-20.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:28049",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "vim-2:8.2.2637-20.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:28050",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "vim-2:8.2.2637-22.el9_6.3"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33313",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782756541"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34102",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1782890503"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1784794818"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1784794778"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1784795112"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1784794289"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1784795076"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-41411\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41411\nhttps://github.com/vim/vim/commit/c78194e41d5a0b05b0ddf383b6679b1503f977fb\nhttps://github.com/vim/vim/releases/tag/v9.2.0357\nhttps://github.com/vim/vim/security/advisories/GHSA-cwgx-gcj7-6qh8"
    ],
    "name": "CVE-2026-41411",
    "mitigation": {
      "value": "Mitigation for this issue involves exercising caution when opening or processing tag files from untrusted sources. Users should avoid loading tag files from unknown or suspicious origins to prevent the execution of arbitrary commands.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-11T00:15:36Z",
    "bugzilla": {
      "description": "GIMP: GIMP: Arbitrary code execution via specially crafted PSD file",
      "id": "2457535",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457535"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\nThe specific flaw exists within the parsing of PSD files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28807.",
      "A flaw was found in GIMP. A remote attacker can exploit this vulnerability by enticing a user to open a specially crafted PSD (Photoshop Document) file. This flaw is due to an integer overflow during the parsing of PSD files, which can lead to arbitrary code execution, allowing the attacker to run malicious code on the affected system."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26168",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gimp-2:2.8.22-1.el7_9.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17533",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gimp:2.8-8100020260512115927.4c9c024f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20552",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gimp:2.8-8040020260520140422.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20552",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gimp:2.8-8040020260520140422.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20553",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gimp:2.8-8060020260520140100.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20553",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gimp:2.8-8060020260520140100.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20553",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gimp:2.8-8060020260520140100.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20554",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gimp:2.8-8080020260520102644.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20554",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gimp:2.8-8080020260520102644.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16484",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-1.el9_7.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19362",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-4.el9_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20691",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gimp-2:2.99.8-3.el9_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25899",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gimp-2:2.99.8-4.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25907",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gimp-2:2.99.8-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25901",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gimp-2:2.99.8-4.el9_6.7"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4150\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4150\nhttps://gitlab.gnome.org/GNOME/gimp/-/commit/00afdabdadeb5457fd897878b1e5aebc3780af10\nhttps://www.zerodayinitiative.com/advisories/ZDI-26-217/"
    ],
    "name": "CVE-2026-4150",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-11T00:15:54Z",
    "bugzilla": {
      "description": "gimp: GIMP: Remote Code Execution via malicious JP2 file parsing",
      "id": "2457533",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457533"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\nThe specific flaw exists within the parsing of JP2 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28863.",
      "A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted JP2 (JPEG 2000) file. This flaw is due to a heap-based buffer overflow during JP2 file parsing, which allows for arbitrary code execution. Successful exploitation enables the attacker to execute code in the context of the current process."
    ],
    "statement": "This is an Important vulnerability in GIMP that could lead to arbitrary code execution. The flaw is a heap-based buffer overflow in the JP2 file parsing component. Exploitation requires user interaction, where a victim must open a specially crafted malicious JP2 file.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16484",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-1.el9_7.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19362",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-4.el9_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20691",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gimp-2:2.99.8-3.el9_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25899",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gimp-2:2.99.8-4.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25907",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gimp-2:2.99.8-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25901",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gimp-2:2.99.8-4.el9_6.7"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "gimp:2.8/gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4152\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4152\nhttps://gitlab.gnome.org/GNOME/gimp/-/commit/f64c9c23ba3c37dc7b875a9fb477c23953b4666e\nhttps://www.zerodayinitiative.com/advisories/ZDI-26-219/"
    ],
    "name": "CVE-2026-4152",
    "mitigation": {
      "value": "To mitigate this issue, users should avoid opening JP2 (JPEG 2000) files from untrusted sources in GIMP. If GIMP is not required, consider removing the `gimp` package to eliminate the attack surface. For systems where GIMP is necessary, running the application within a sandboxed environment can limit the potential impact of successful exploitation. Removing this package may affect other applications that depend on GIMP.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-11T00:16:01Z",
    "bugzilla": {
      "description": "gimp: GIMP: Remote Code Execution via PSP file parsing",
      "id": "2457536",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457536"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\nThe specific flaw exists within the parsing of PSP files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28874.",
      "A flaw was found in GIMP. A remote attacker could exploit this vulnerability by enticing a user to open a specially crafted PSP (PaintShop Pro) file. This flaw is caused by a heap-based buffer overflow, where the application does not properly validate the length of user-supplied data. Successful exploitation can lead to arbitrary code execution in the context of the current process."
    ],
    "statement": "This is an Important vulnerability in GIMP that could lead to arbitrary code execution. The flaw requires user interaction, as an attacker must entice a user to open a specially crafted PSP (PaintShop Pro) file. Red Hat products are affected if GIMP is installed and used to open untrusted PSP files.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26168",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gimp-2:2.8.22-1.el7_9.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17533",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gimp:2.8-8100020260512115927.4c9c024f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20552",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gimp:2.8-8040020260520140422.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20552",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gimp:2.8-8040020260520140422.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20553",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gimp:2.8-8060020260520140100.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20553",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gimp:2.8-8060020260520140100.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20553",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gimp:2.8-8060020260520140100.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20554",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gimp:2.8-8080020260520102644.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20554",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gimp:2.8-8080020260520102644.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16484",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-1.el9_7.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19362",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-4.el9_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20691",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gimp-2:2.99.8-3.el9_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25899",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gimp-2:2.99.8-4.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25907",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gimp-2:2.99.8-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25901",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gimp-2:2.99.8-4.el9_6.7"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4153\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4153\nhttps://gitlab.gnome.org/GNOME/gimp/-/commit/98cb1371fd4e22cca75017ea3252dc32fc218712\nhttps://www.zerodayinitiative.com/advisories/ZDI-26-220/"
    ],
    "name": "CVE-2026-4153",
    "mitigation": {
      "value": "To mitigate this vulnerability, users should avoid opening untrusted PSP (PaintShop Pro) files with GIMP. Restricting the sources of PSP files to only trusted origins can reduce the risk of exploitation.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-11T00:16:10Z",
    "bugzilla": {
      "description": "gimp: GIMP: Remote Code Execution via XPM File Parsing Integer Overflow",
      "id": "2457530",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457530"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\nThe specific flaw exists within the parsing of XPM files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28901.",
      "A flaw was found in GIMP. Remote attackers can exploit this vulnerability by tricking a user into opening a malicious XPM (X PixMap) image file. This can lead to an an integer overflow during file processing, allowing the attacker to execute arbitrary code on the affected system."
    ],
    "statement": "This is an Important vulnerability in GIMP that could lead to arbitrary code execution. Exploitation requires a user to open a specially crafted XPM image file. Red Hat Enterprise Linux systems with GIMP installed are affected if users process untrusted XPM files.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26168",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gimp-2:2.8.22-1.el7_9.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17533",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gimp:2.8-8100020260512115927.4c9c024f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20552",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gimp:2.8-8040020260520140422.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20552",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gimp:2.8-8040020260520140422.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20553",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gimp:2.8-8060020260520140100.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20553",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gimp:2.8-8060020260520140100.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20553",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gimp:2.8-8060020260520140100.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20554",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gimp:2.8-8080020260520102644.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20554",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gimp:2.8-8080020260520102644.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16484",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-1.el9_7.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19362",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-4.el9_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20691",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gimp-2:2.99.8-3.el9_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25899",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gimp-2:2.99.8-4.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25907",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gimp-2:2.99.8-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25901",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gimp-2:2.99.8-4.el9_6.7"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4154\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4154\nhttps://gitlab.gnome.org/GNOME/gimp/-/commit/2e7ed91793792d9e980b2df4c829e9aa60459253\nhttps://www.zerodayinitiative.com/advisories/ZDI-26-221/"
    ],
    "name": "CVE-2026-4154",
    "mitigation": {
      "value": "To mitigate this issue, users should avoid opening XPM image files from untrusted sources. On systems where GIMP is not required, the `gimp` package can be removed. Removing desktop-related packages may impact graphical environment functionality.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-27T08:59:50Z",
    "bugzilla": {
      "description": "Apache MINA: Apache MINA: Arbitrary code execution via classname allowlist bypass",
      "id": "2463177",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2463177"
    },
    "cvss3": {
      "cvss3_base_score": "9.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-502",
    "details": [
      "Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed.\nThe fix checks if the class is present in the accepted class filter before calling Class.forName(). \nAffected versions are Apache MINA 2.0.0 <= 2.0.27, 2.1.0 <= 2.1.10, and\n2.2.0 <= 2.2.5.\nThe problem is resolved in Apache MINA 2.0.28, 2.1.11, and 2.2.6 by \napplying the classname allowlist earlier.\nAffected are applications using Apache MINA that call  IoBuffer.getObject().\nApplications using Apache MINA are advised to upgrade.",
      "A flaw was found in Apache MINA. A remote attacker could exploit a vulnerability in the `AbstractIoBuffer.resolveClass()` method, which failed to properly validate class names for static classes or primitive types. This bypasses the intended security control, known as a classname allowlist, allowing an attacker to execute arbitrary code on systems running applications that use Apache MINA and call `IoBuffer.getObject()`. This could lead to a complete compromise of the affected system."
    ],
    "statement": "Red Hat products are affected by this vulnerability. However, the vulnerable code cannot be reached and therefore are not vulnerable. Due to this reason, this flaw has been rated with a low severity.",
    "affected_release": [
      {
        "product_name": "Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17668",
        "cpe": "cpe:/a:redhat:apache_camel_spring_boot:4.18",
        "package": "mina-core"
      }
    ],
    "package_state": [
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "jenkins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "jenkins-2-plugins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "Red Hat AMQ Broker 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:amq_broker:7"
      },
      {
        "product_name": "Red Hat Data Grid 8",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_data_grid:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "javapackages-tools:201801/maven-wagon",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "maven:3.9/maven-wagon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "maven-wagon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Fuse 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_fuse:7"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform 8",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jbosseapxp"
      },
      {
        "product_name": "Red Hat Process Automation 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
      },
      {
        "product_name": "Red Hat Single Sign-On 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
      },
      {
        "product_name": "streams for Apache Kafka 2",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:amq_streams:2"
      },
      {
        "product_name": "streams for Apache Kafka 3",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:amq_streams:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-41635\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41635\nhttps://lists.apache.org/thread/1l91w1mqsb3lwfd504fs045ylxntt2tm"
    ],
    "name": "CVE-2026-41635",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-29T10:15:50Z",
    "bugzilla": {
      "description": "gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility",
      "id": "2494158",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494158"
    },
    "cvss3": {
      "cvss3_base_score": "6.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-59",
    "details": [
      "GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks.\nA local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.\nThis issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269",
      "A flaw was found in the `gzexe` utility of GNU `gzip`. When the `mktemp` utility is not available, `gzexe` creates temporary files with predictable names based on the process ID. A local attacker can exploit this by pre-creating a symbolic link to an arbitrary file at the predicted temporary file path. This can lead to a Time-of-Check to Time-of-Use (TOCTOU) condition, allowing the attacker to overwrite arbitrary files on the system."
    ],
    "statement": "A flaw was found in the gzexe utility of GNU gzip. When the mktemp utility is not available in the user's PATH, gzexe creates temporary files with predictable names based on the process ID. A local attacker can exploit this by creating a symbolic link at the predicted temporary file path, leading to a TOCTOU race condition that allows arbitrary file overwrite. On Red Hat Enterprise Linux, mktemp is provided by coreutils which is always installed, making the vulnerable fallback code path effectively unreachable in standard deployments.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33771",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gzip-main-1.14-2.2.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gzip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "gzip",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "gzip",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gzip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gzip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-sshd-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-41991\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41991\nhttps://cert.pl/en/posts/2026/04/CVE-2026-41991/\nhttps://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269\nhttps://www.gnu.org/software/gzip/"
    ],
    "name": "CVE-2026-41991",
    "mitigation": {
      "value": "Ensure that the mktemp utility (provided by the coreutils package) is available in PATH when using the gzexe utility. On Red Hat Enterprise Linux, mktemp is installed by default and no additional action is needed.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-14T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation.\nBy decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.\n\nThis issue has been fixed in the commit 63dbf6b3b9e6e781df1a6a64e609b10e23969681"
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-41992\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41992"
    ],
    "name": "CVE-2026-41992",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-12T13:28:46Z",
    "bugzilla": {
      "description": "dovecot: Dovecot: Denial of Service via excessive IMAP bracing",
      "id": "2476476",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476476"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.",
      "A flaw was found in Dovecot. A remote attacker can exploit this vulnerability by sending excessive open braces over the Internet Message Access Protocol (IMAP), leading to uncontrolled memory usage. This can cause the affected system to consume memory up to its configured limit, resulting in a Denial of Service (DoS)."
    ],
    "statement": "A remote attacker can trigger this flaw simply by sending specially crafted IMAP requests to the Dovecot server, requiring no complex interactions.\nThe vulnerability is strictly limited to a Denial of Service (DoS) via memory exhaustion and does not allow for data exfiltration, privilege escalation, or remote code execution. Furthermore, the impact is contained because the memory consumption is restricted to the process's configured limit, preventing a complete system-wide crash.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41988",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "dovecot-1:2.3.21-19.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42091",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "dovecot-1:2.3.21-16.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49513",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "dovecot-1:2.2.36-8.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46532",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "dovecot-1:2.3.16-8.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46380",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "dovecot-1:2.3.8-9.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46380",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "dovecot-1:2.3.8-9.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46379",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "dovecot-1:2.3.16-2.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46379",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "dovecot-1:2.3.16-2.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46381",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "dovecot-1:2.3.16-3.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46381",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "dovecot-1:2.3.16-3.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41905",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "dovecot-1:2.3.16-18.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44373",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "dovecot-1:2.3.16-8.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44357",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "dovecot-1:2.3.16-11.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44355",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "dovecot-1:2.3.16-15.el9_6.2"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "dovecot",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42006\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42006\nhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0002.json"
    ],
    "name": "CVE-2026-42006",
    "mitigation": {
      "value": "To mitigate this issue, administrators can configure the `vsz_limit` setting for the Dovecot IMAP process to a lower value. This limits the virtual memory size available to the IMAP process, preventing excessive memory consumption.\nExample configuration in `/etc/dovecot/conf.d/10-master.conf`:\n```\nservice imap {\nvsz_limit = 256M\n}\n```\nAfter modifying the configuration, restart the Dovecot service for the changes to take effect.\n```bash\nsystemctl restart dovecot\n```\nSetting `vsz_limit` too low may impact legitimate IMAP operations. \n*Restarting the dovecot service will temporarily interrupt mail services.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-29T00:00:00Z",
    "bugzilla": {
      "description": "gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability",
      "id": "2467279",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467279"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-475",
    "details": [
      "A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.",
      "A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service."
    ],
    "statement": "The impact for this flaw has been downgraded on Red Hat Enterprise Linux due to the following reason:\n- The number of elements passed to the vulnerable function at runtime is known and is at most 6 and the element size is sufficiently small. glibc’s qsort implementation will not exercise the quick sort code path, which would otherwise cause an infloop or out-of-bound write.",
    "acknowledgement": "Red Hat would like to thank Joshua Rogers (AISLE Research Team) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20613",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gnutls-0:3.8.10-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26409",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gnutls-0:3.8.9-9.el10_0.19"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34372",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gnutls-0:3.3.29-9.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41921",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gnutls-0:3.7.6-21.el9_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32962",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gnutls-0:3.8.3-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30004",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gnutls-0:3.8.3-6.el9_6.4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:40762",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202607151909-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:34788",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "rhcos-4.20.9.6.202607010620-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:34764",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "rhcos-4.21.9.6.202607011303-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:29794",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202606230855-0"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36004",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1782951051"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36005",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1782951012"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36006",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782951244"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:13274",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gnutls-main-3.8.13-1.hum1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42009\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42009\nhttps://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2"
    ],
    "name": "CVE-2026-42009",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-29T00:00:00Z",
    "bugzilla": {
      "description": "gnutls: gnutls: Authentication Bypass via NUL Character in Username",
      "id": "2467289",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467289"
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-170",
    "details": [
      "A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.",
      "A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process."
    ],
    "acknowledgement": "Red Hat would like to thank Joshua Rogers (AISLE Research Team) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20613",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gnutls-0:3.8.10-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26409",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gnutls-0:3.8.9-9.el10_0.19"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41921",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gnutls-0:3.7.6-21.el9_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32962",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gnutls-0:3.8.3-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30004",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gnutls-0:3.8.3-6.el9_6.4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:40762",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202607151909-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.20",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:34788",
        "cpe": "cpe:/a:redhat:openshift:4.20::el9",
        "package": "rhcos-4.20.9.6.202607010620-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.21",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:34764",
        "cpe": "cpe:/a:redhat:openshift:4.21::el9",
        "package": "rhcos-4.21.9.6.202607011303-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:34790",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202606301732-0"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36004",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1782951051"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36005",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1782951012"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:36006",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782951244"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:13274",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gnutls-main-3.8.13-1.hum1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42010\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42010\nhttps://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-4"
    ],
    "name": "CVE-2026-42010",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-29T00:00:00Z",
    "bugzilla": {
      "description": "gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs",
      "id": "2467441",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467441"
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-295",
    "details": [
      "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.",
      "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information."
    ],
    "acknowledgement": "Red Hat would like to thank Oleh Konko (1Seal) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20613",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gnutls-0:3.8.10-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26409",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gnutls-0:3.8.9-9.el10_0.19"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43575",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gnutls-0:3.3.29-9.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41921",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gnutls-0:3.7.6-21.el9_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32962",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gnutls-0:3.8.3-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30004",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gnutls-0:3.8.3-6.el9_6.4"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:13274",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gnutls-main-3.8.13-1.hum1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42012\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42012\nhttps://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-7"
    ],
    "name": "CVE-2026-42012",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-29T00:00:00Z",
    "bugzilla": {
      "description": "gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name",
      "id": "2467448",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467448"
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-295",
    "details": [
      "A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.",
      "A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks."
    ],
    "acknowledgement": "Red Hat would like to thank Haruto Kimura (Stella) and Joshua Rogers (AISLE Research Team) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20613",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gnutls-0:3.8.10-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26409",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gnutls-0:3.8.9-9.el10_0.19"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43575",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gnutls-0:3.3.29-9.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41921",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gnutls-0:3.7.6-21.el9_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32962",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gnutls-0:3.8.3-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30004",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gnutls-0:3.8.3-6.el9_6.4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:40762",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202607151909-0"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:13274",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gnutls-main-3.8.13-1.hum1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42013\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42013\nhttps://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-8"
    ],
    "name": "CVE-2026-42013",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-29T00:00:00Z",
    "bugzilla": {
      "description": "gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin",
      "id": "2467451",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467451"
    },
    "cvss3": {
      "cvss3_base_score": "6.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.",
      "A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path."
    ],
    "acknowledgement": "Red Hat would like to thank Joshua Rogers (AISLE Research Team) and Luigino Camastra for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20613",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gnutls-0:3.8.10-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26409",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gnutls-0:3.8.9-9.el10_0.19"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43575",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gnutls-0:3.3.29-9.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41921",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gnutls-0:3.7.6-21.el9_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32962",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gnutls-0:3.8.3-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30004",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gnutls-0:3.8.3-6.el9_6.4"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:13274",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gnutls-main-3.8.13-1.hum1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42014\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42014\nhttps://gitlab.com/gnutls/gnutls/-/issues/1766\nhttps://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-9"
    ],
    "name": "CVE-2026-42014",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-29T00:00:00Z",
    "bugzilla": {
      "description": "gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling",
      "id": "2467678",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467678"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-193",
    "details": [
      "A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.",
      "A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts."
    ],
    "acknowledgement": "Red Hat would like to thank Zou Dikai for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20613",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gnutls-0:3.8.10-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26409",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gnutls-0:3.8.9-9.el10_0.19"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43575",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gnutls-0:3.3.29-9.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41921",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gnutls-0:3.7.6-21.el9_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32962",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gnutls-0:3.8.3-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30004",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gnutls-0:3.8.3-6.el9_6.4"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:13274",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gnutls-main-3.8.13-1.hum1",
        "impact": "low"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42015\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42015\nhttps://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-11"
    ],
    "name": "CVE-2026-42015",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-11T19:46:50Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service due to an overflow vulnerability in MIFF file processing",
      "id": "2471934",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2471934"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-131",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9.13-46, a malicious MIFF file could trigger an overflow when a user opens it in the display tool and right-clicks a tile to invoke the Load / Update menu item. This vulnerability is fixed in 7.1.2-21 and 6.9.13-46.",
      "A flaw was found in ImageMagick. A user opening a specially crafted MIFF (Magick Image File Format) file in the display tool and right-clicking a tile to invoke the Load / Update menu item could trigger an overflow vulnerability. This overflow could lead to a denial of service, making the application unavailable."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42050\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42050\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7mxf-ff4f-jj7p"
    ],
    "name": "CVE-2026-42050",
    "mitigation": {
      "value": "Users should avoid opening or interacting with untrusted MIFF (Magick Image File Format) files using the ImageMagick display tool. If the ImageMagick package is not essential for image display or other critical system functions, consider removing it. Be aware that removing ImageMagick may impact other applications that rely on its image processing capabilities.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-17T14:04:32Z",
    "bugzilla": {
      "description": "nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers",
      "id": "2489866",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2489866"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in NGINX. When NGINX is configured to proxy HTTP/2 traffic using the ngx_http_proxy_v2_module or ngx_http_grpc_module with specific settings, a remote, unauthenticated attacker can send specially crafted large headers. This can trigger a heap-based buffer overflow, leading to a restart of the NGINX worker process and a Denial of Service (DoS). Under certain conditions, such as when Address Space Layout Randomization (ASLR) is disabled or bypassed, this vulnerability could also allow for arbitrary code execution."
    ],
    "statement": "This issue is classified as Important severity primarily because:\nConditions for Exploitation: A remote, unauthenticated attacker can only exploit this if NGINX is explicitly configured to proxy HTTP/2 traffic using the ngx_http_proxy_v2_module or ngx_http_grpc_module.\nImpact Limitations: While the flaw reliably causes a Denial of Service (worker restart), achieving arbitrary code execution is highly complex in modern environments as it requires the attacker to bypass or disable Address Space Layout Randomization (ASLR)",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36364",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "nginx-2:1.26.3-6.el10_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38847",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nginx:1.24-8100020260707171317.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36331",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx-2:1.20.1-28.el9_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36618",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.24-9080020260707164406.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36639",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.26-9080020260707110000.9"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46836",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1784821750"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-19T00:00:00Z",
        "advisory": "RHSA-2026:27197",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nginx-main-1.30.3-2.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1784794818"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1784794778"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1784795076"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/ocs-client-console-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Affected",
        "package_name": "odf4/odf-console-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/odf-multicluster-console-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42055\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42055\nhttps://my.f5.com/manage/s/article/K000161584"
    ],
    "name": "CVE-2026-42055",
    "mitigation": {
      "value": "To mitigate this vulnerability, ensure that the `ignore_invalid_headers` directive is set to `on` in your NGINX configuration, or reduce the size specified by the `large_client_header_buffers` directive to 2 megabytes or less. These changes require an NGINX service reload or restart to take effect. Reloading the NGINX service is generally safe, but a restart will briefly interrupt service.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-30T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "mod_sql in ProFTPD before 1.3.10rc1 allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM)."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42167\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42167"
    ],
    "name": "CVE-2026-42167",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-09T19:37:08Z",
    "bugzilla": {
      "description": "ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses",
      "id": "2468495",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468495"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-606",
    "details": [
      "Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client's CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.",
      "A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client's CPU being exhausted, resulting in a denial of service (DoS) attack."
    ],
    "statement": "Red Hat has rated this flaw as Moderate because a malicious IMAP server can trigger excessive CPU consumption, resulting in a denial-of-service (DoS) condition in client applications using the affected Net::IMAP library. Successful exploitation requires interaction with a hostile server, and the impact is strictly limited to resource exhaustion of the client process. The vulnerability does not allow code execution, privilege escalation, or unauthorized access to data.\nRegarding Red Hat Satellite: the Satellite-shipped puppet-agent package may include Net::IMAP / net-imap files under /opt/puppetlabs as part of the bundled Puppet Ruby runtime. Satellite does not use Net::IMAP for its supported email notification functionality (SMTP is used instead), and the vulnerable IMAP client operations are not exercised on a supported Satellite attack path. Presence of these files in puppet-agent therefore does not change the assessment that these CVEs are not applicable to Red Hat Satellite. Scanner findings based solely on on-disk gem presence should be treated as false positives for Satellite product impact.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33540",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "ruby4.0-0:4.0.3-35.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33565",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "ruby-0:3.3.10-13.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35895",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "ruby-0:3.3.10-11.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33515",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "ruby:3.3-8100020260615131010.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33576",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "ruby:3.3-9080020260615131001.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33577",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "ruby:4.0-9080020260619130154.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36099",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "ruby:3.3-9040020260630065449.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37238",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "ruby:3.3-9060020260630075016.9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33551",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby4-0-main-4.0.0-33.4.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33552",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby3-4-main-3.4.8-31.2.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33721",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby3-3-main-3.3.10-23.2.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38694",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby3-4-main-3.4.10-31.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp21/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp21/zync",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp22/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp22/zync",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp2/system-rhel7",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp2/system-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp2/system-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp2/zync-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp2/zync-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42245\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42245\nhttps://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96\nhttps://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda\nhttps://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819\nhttps://github.com/ruby/net-imap/releases/tag/v0.4.24\nhttps://github.com/ruby/net-imap/releases/tag/v0.5.14\nhttps://github.com/ruby/net-imap/releases/tag/v0.6.4\nhttps://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw"
    ],
    "name": "CVE-2026-42245",
    "mitigation": {
      "value": "To reduce the risk of a denial of service, ensure that applications using the Net::IMAP library are configured to connect exclusively to trusted IMAP servers. Avoid connecting to untrusted or unverified IMAP services, as a hostile server can exploit this vulnerability. This operational control helps prevent exposure to malicious IMAP response processing.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-09T19:33:17Z",
    "bugzilla": {
      "description": "net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS",
      "id": "2468499",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468499"
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-325",
    "details": [
      "Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return \"successfully\", without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.",
      "A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled."
    ],
    "statement": "This vulnerability affects the STARTTLS functionality in the Ruby net-imap library. Red Hat Product Security has assessed this issue as an Important severity vulnerability.\nAttack Complexity is considered High (AC:H), because successful exploitation requires an attacker capable of intercepting and modifying network traffic and successfully winning a timing race during the STARTTLS negotiation process.\nThis may allow exposure of authentication credentials, email contents, and other sensitive information, as well as unauthorized modification of data transmitted over the affected connection.\n```\nRed Hat's ruby packages distribute net-imap as a default bundled gem, the ruby package itself is listed affected. Applications relying on the system-provided Ruby installation to handle IMAP connections may be exposed to this flaw.\nRed Hat 3scale API Management uses net-imap which is a transitive dependency of mail, which is a dependency of actionmailer and actionmailbox. The images doesn’t load them or use them in any way, hence, they are not affected.\n```",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33540",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "ruby4.0-0:4.0.3-35.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33565",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "ruby-0:3.3.10-13.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35895",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "ruby-0:3.3.10-11.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37397",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "ruby-0:2.0.0.648-39.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33514",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "ruby:2.5-8100020260615131019.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33515",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "ruby:3.3-8100020260615131010.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35866",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "ruby:2.5-8040020260630124058.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35866",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "ruby:2.5-8040020260630124058.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35867",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "ruby:2.5-8060020260630123825.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35867",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "ruby:2.5-8060020260630123825.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34076",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "ruby:2.5-8080020260625114827.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34076",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "ruby:2.5-8080020260625114827.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33512",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "ruby-0:3.0.7-167.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33576",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "ruby:3.3-9080020260615131001.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33577",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "ruby:4.0-9080020260619130154.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35834",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "ruby-0:3.0.4-161.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33630",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "ruby-0:3.0.7-162.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36099",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "ruby:3.3-9040020260630065449.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33462",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "ruby-0:3.0.7-165.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37238",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "ruby:3.3-9060020260630075016.9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33551",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby4-0-main-4.0.0-33.4.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33552",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby3-4-main-3.4.8-31.2.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33721",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby3-3-main-3.3.10-23.2.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38694",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby3-4-main-3.4.10-31.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp21/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp21/zync",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp22/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp22/zync",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp2/system-rhel7",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp2/system-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp2/system-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp2/zync-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Not affected",
        "package_name": "3scale-amp2/zync-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42246\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42246\nhttps://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618\nhttps://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e\nhttps://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c\nhttps://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da\nhttps://github.com/ruby/net-imap/releases/tag/v0.3.10\nhttps://github.com/ruby/net-imap/releases/tag/v0.4.24\nhttps://github.com/ruby/net-imap/releases/tag/v0.5.14\nhttps://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp"
    ],
    "name": "CVE-2026-42246",
    "mitigation": {
      "value": "As a temporary workaround, Users are strongly encouraged to switch from explicit TLS upgrading mechanisms (STARTTLS on port 143) to Implicit TLS connections (such as IMAPS on port 993).\nBy enforcing implicit TLS via port 993 from the initial socket creation step, the connection is mathematically protected against packet injection and connection degradation tactics entirely, bypassing the vulnerable implementation path.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-28T13:15:19Z",
    "bugzilla": {
      "description": "bzip2: bzip2: Denial of Service in bzip2recover via a specially crafted file",
      "id": "2482704",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482704"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-193",
    "details": [
      "bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67",
      "A flaw was found in bzip2. The bzip2recover utility contains an off-by-one error that allows a local attacker to cause an out-of-bounds write to a global buffer by processing a specially crafted file. This memory corruption can lead to a crash, resulting in a Denial of Service (DoS)."
    ],
    "statement": "A Moderate impact denial of service flaw exists in the `bzip2recover` utility within bzip2. This vulnerability allows a local attacker to trigger an out-of-bounds write and crash the application by processing a specially crafted compressed file. Exploitation requires user interaction with a malicious file, limiting the attack vector to scenarios where untrusted bzip2 archives are processed by the recovery utility.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-26T00:00:00Z",
        "advisory": "RHSA-2026:30268",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "bzip2-main-1.0.8-23.2.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:0"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:1"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/mcp-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/ansible-builder-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/mcp-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "bzip2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gjs",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "goose",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libkrun",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rust-sequoia-sq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "bzip2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "bzip2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "bzip2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-bzip2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mozjs60",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "bzip2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "goose",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "rust-podman-sequoia",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-llm-d-inference-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Update Service",
        "fix_state": "Fix deferred",
        "package_name": "openshift-update-service/openshift-update-service-rhel8",
        "cpe": "cpe:/a:redhat:openshift_update_service:5"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "python3.12-maturin",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "python-maturin",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-host-inventory-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vmaas-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vulnerability-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Fix deferred",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42250\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42250\nhttps://cert.pl/en/posts/2026/05/CVE-2026-42250/\nhttps://sourceware.org/bzip2/"
    ],
    "name": "CVE-2026-42250",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-09T19:39:48Z",
    "bugzilla": {
      "description": "net-imap: Net::IMAP: Arbitrary IMAP command injection via CRLF sequences in unvalidated input",
      "id": "2468494",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468494"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-93",
    "details": [
      "Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.",
      "A flaw was found in Net::IMAP (before 0.4.24, 0.5.14, and 0.6.4). Several commands accept raw string arguments sent to the server without validation or escaping; if derived from user-controlled input, CRLF sequences allow injection of arbitrary IMAP commands."
    ],
    "statement": "Net::IMAP is vulnerable to IMAP command injection in versions before 0.4.24, 0.5.14, and 0.6.4. Several client commands accept raw string arguments that are sent to the IMAP server without CRLF validation or escaping; if application code passes user-controlled data into those arguments, an attacker can inject additional IMAP commands by embedding carriage return and line feed sequences. Red Hat impact is concentrated in Ruby-based products that bundle a vulnerable net-imap gem, including RHEL Ruby module streams, OpenShift Serverless (hummingbird) Ruby runtimes, and 3scale AMP components (zync/system) that use Net::IMAP with externally influenced input; Perl IMAP client packages on Fedora are a separate codebase and are not affected.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:36978",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby4-0-main-4.0.5-35.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38694",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby3-4-main-3.4.10-31.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:40380",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby3-3-main-3.3.10-23.4.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp21/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp21/zync",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp22/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "3scale-amp22/zync",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/system-rhel7",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/system-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/system-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "3scale-amp2/zync-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "3scale-amp2/zync-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Out of support scope",
        "package_name": "ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "ruby4.0",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "ruby:3.3/ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ruby:3.3/ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ruby:4.0/ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42257\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42257\nhttps://github.com/ruby/net-imap/releases/tag/v0.4.24\nhttps://github.com/ruby/net-imap/releases/tag/v0.5.14\nhttps://github.com/ruby/net-imap/releases/tag/v0.6.4\nhttps://github.com/ruby/net-imap/security/advisories/GHSA-hm49-wcqc-g2xg"
    ],
    "name": "CVE-2026-42257",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-09T19:40:49Z",
    "bugzilla": {
      "description": "ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments",
      "id": "2468498",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468498"
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-93",
    "details": [
      "Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.",
      "A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts."
    ],
    "statement": "This command injection flaw is limited to the injection of IMAP commands. Arbitrary code execution is not a risk of this flaw and so the impact is limited to email systems.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33540",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "ruby4.0-0:4.0.3-35.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33565",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "ruby-0:3.3.10-13.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35895",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "ruby-0:3.3.10-11.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37397",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "ruby-0:2.0.0.648-39.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33514",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "ruby:2.5-8100020260615131019.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33515",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "ruby:3.3-8100020260615131010.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35866",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "ruby:2.5-8040020260630124058.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35866",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "ruby:2.5-8040020260630124058.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35867",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "ruby:2.5-8060020260630123825.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35867",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "ruby:2.5-8060020260630123825.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34076",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "ruby:2.5-8080020260625114827.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34076",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "ruby:2.5-8080020260625114827.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33512",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "ruby-0:3.0.7-167.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33576",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "ruby:3.3-9080020260615131001.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33577",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "ruby:4.0-9080020260619130154.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35834",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "ruby-0:3.0.4-161.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33630",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "ruby-0:3.0.7-162.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36099",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "ruby:3.3-9040020260630065449.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33462",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "ruby-0:3.0.7-165.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37238",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "ruby:3.3-9060020260630075016.9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:36978",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby4-0-main-4.0.5-35.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38694",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby3-4-main-3.4.10-31.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:40380",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "ruby3-3-main-3.3.10-23.4.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Under investigation",
        "package_name": "3scale-amp21/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Under investigation",
        "package_name": "3scale-amp21/zync",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Under investigation",
        "package_name": "3scale-amp22/system",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Under investigation",
        "package_name": "3scale-amp22/zync",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Under investigation",
        "package_name": "3scale-amp2/system-rhel7",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Under investigation",
        "package_name": "3scale-amp2/system-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Under investigation",
        "package_name": "3scale-amp2/system-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Under investigation",
        "package_name": "3scale-amp2/zync-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Under investigation",
        "package_name": "3scale-amp2/zync-rhel9",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "ruby",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42258\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42258\nhttps://github.com/ruby/net-imap/releases/tag/v0.4.24\nhttps://github.com/ruby/net-imap/releases/tag/v0.5.14\nhttps://github.com/ruby/net-imap/releases/tag/v0.6.4\nhttps://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px"
    ],
    "name": "CVE-2026-42258",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-13T20:20:29Z",
    "bugzilla": {
      "description": "python-twisted: Twisted: Denial of Service via crafted DNS packets in twisted.names",
      "id": "2477296",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477296"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-835",
    "details": [
      "Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.",
      "A flaw was found in Twisted, specifically within the `twisted.names` module. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted TCP DNS packet containing deeply chained compression pointers. This can lead to resource exhaustion, causing the single-threaded Twisted reactor to hang and effectively freezing the server, resulting in a Denial of Service (DoS)."
    ],
    "statement": "A flaw was found in the twisted.names DNS module of the Python Twisted framework. A remote unauthenticated attacker can send a single crafted TCP DNS packet containing deeply chained compression pointers and thousands of question records to hang the single-threaded Twisted reactor, effectively freezing the server. The visited set that prevents infinite loops has no limit on total pointer dereferences and is reset per question record, allowing resource exhaustion.\nRed Hat Ansible Automation Platform components (automation-controller, EDA controller, Lightspeed) bundle python-twisted but use it via Daphne as an ASGI server. These components do not import or execute twisted.names, so the vulnerable DNS decompression code is never reached.\nRed Hat Enterprise Linux 6 ships python-twisted but is out of support scope (ELS does not cover python-twisted).",
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python-twisted",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "python-twisted",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-jsonschema",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "python-twisted",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42304\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42304\nhttps://github.com/twisted/twisted/security/advisories/GHSA-grgv-6hw6-v9g4"
    ],
    "name": "CVE-2026-42304",
    "mitigation": {
      "value": "There is no mitigation for this issue. Applications using twisted.names for DNS resolution or as a DNS server should update to a fixed version of Twisted when available.\nUpgrade to a patched version (>= 26.4.0rc2).",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-08T22:38:53Z",
    "bugzilla": {
      "description": "Vim: Vim: Arbitrary code execution via OS command injection in netrw plugin",
      "id": "2468403",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468403"
    },
    "cvss3": {
      "cvss3_base_score": "4.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-78",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.",
      "A flaw was found in Vim’s netrw plugin. Improper sanitization of specially crafted filenames or URLs could allow shell metacharacters to be included in temporary filenames passed to external commands. A local attacker could exploit this issue to trigger unintended shell command execution when a user opens malicious content using affected netrw functionality."
    ],
    "statement": "This vulnerability affects Vim’s netrw plugin URL and file handling functionality. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability.\nA local attacker may craft malicious filenames or URLs containing shell metacharacters that trigger unintended shell command execution when opened by a victim using affected netrw functionality in Vim. Successful exploitation requires user interaction because the victim must open attacker-controlled content.\nRed Hat therefore assessed the Confidentiality and Integrity impacts as Low (C:L/I:L), with no direct Availability impact (A:N).",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42307\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42307\nhttps://github.com/vim/vim/commit/405e2fb6d54d5653523809e2853d99d1c000a5fc\nhttps://github.com/vim/vim/releases/tag/v9.2.0383\nhttps://github.com/vim/vim/security/advisories/GHSA-85ch-p2qr-m5gx"
    ],
    "name": "CVE-2026-42307",
    "mitigation": {
      "value": "Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-10T21:25:35Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Information disclosure via malicious IPTC input file",
      "id": "2487735",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487735"
    },
    "cvss3": {
      "cvss3_base_score": "5.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when writing an IPTC output file a malicious input file could cause an out of bounds read of a single byte. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.",
      "A flaw was found in ImageMagick, a software used for editing and manipulating digital images. A local attacker could exploit this vulnerability by providing a malicious input file. When ImageMagick attempts to write an IPTC output file, this malicious input could cause the software to read beyond its allocated memory. This out-of-bounds read may lead to the disclosure of sensitive information or a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42326\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42326\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7wff-wpr6-vmhm"
    ],
    "name": "CVE-2026-42326",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-27T05:50:36Z",
    "bugzilla": {
      "description": "uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs",
      "id": "2463159",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2463159"
    },
    "cvss3": {
      "cvss3_base_score": "4.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.",
      "A flaw was found in uriparser. This vulnerability occurs due to numeric truncation in text range comparison when an application processes extremely long Uniform Resource Identifiers (URIs), specifically those with lengths in gigabytes. A local attacker could exploit this flaw by providing a malformed, excessively long URI, leading to a Denial of Service (DoS) condition where the application becomes unavailable."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12430",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "uriparser-main-1.0.1-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "uriparser",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "uriparser",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42371\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42371\nhttps://github.com/uriparser/uriparser/pull/298\nhttps://uriparser.github.io"
    ],
    "name": "CVE-2026-42371",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-26T00:17:19Z",
    "bugzilla": {
      "description": "perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access",
      "id": "2481314",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481314"
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-22",
    "details": [
      "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\nA subsequent open through the extracted name reads or writes the attacker chosen path.",
      "A flaw was found in perl-Archive-Tar. Versions before 3.08 for Perl are vulnerable to a path traversal issue. An attacker can craft a malicious tar archive containing symlinks with targets outside the intended extraction directory. This vulnerability allows the attacker to read or write to arbitrary files on the system, leading to potential information disclosure or data corruption."
    ],
    "statement": "This is an Important vulnerability in `perl-Archive-Tar` that allows for arbitrary file access due to a path traversal flaw when extracting specially crafted tar archives. An attacker could exploit this by creating a malicious archive containing symlinks that point outside the intended extraction directory, potentially leading to unauthorized information disclosure or data corruption on the system. This risk is elevated in environments where untrusted archives are processed.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30857",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "perl-Archive-Tar-0:3.02-512.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30851",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "perl:5.32-8100020260616084412.651ee29f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30852",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "perl-Archive-Tar-0:2.30-2.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30856",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "perl-Archive-Tar-0:2.38-6.el9_8.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "perl-Archive-Tar",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42496\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42496\nhttps://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch\nhttps://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes\nhttps://www.cve.org/CVERecord?id=CVE-2026-42497"
    ],
    "name": "CVE-2026-42496",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-12T15:17:56Z",
    "bugzilla": {
      "description": "tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.",
      "id": "2476516",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476516"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-201",
    "details": [
      "Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109.\nUsers are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.",
      "A flaw was found in Apache Tomcat. During WebSocket authentication, the HTTP Authentication Header can be exposed to unexpected hosts. This vulnerability leads to information disclosure, potentially allowing an attacker to gain access to sensitive authentication credentials."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat JBoss Web Server 6.2.4",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43402",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2",
        "package": "tomcat-coyote"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 10",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 8",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el9jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0.0",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39189",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
        "package": "tomcat-coyote"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 10",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 8",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 9",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el9jws"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13745",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.22-0.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16528",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.55-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Certificate System 10",
        "fix_state": "Fix deferred",
        "package_name": "redhat-pki:10/jss",
        "cpe": "cpe:/a:redhat:certificate_system:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Out of support scope",
        "package_name": "jss",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "mod_proxy_cluster",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jss",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mod_proxy_cluster",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Fuse 7",
        "fix_state": "Out of support scope",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jboss_fuse:7"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-mod_cluster-native",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-mod_proxy_cluster",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
        "fix_state": "Not affected",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jbosseapxp"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Out of support scope",
        "package_name": "jws5-mod_cluster",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Out of support scope",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Not affected",
        "package_name": "jws6-mod_cluster",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Process Automation 7",
        "fix_state": "Out of support scope",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
      },
      {
        "product_name": "Red Hat Single Sign-On 7",
        "fix_state": "Out of support scope",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42498\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42498\nhttps://lists.apache.org/thread/n61zwf75jrv09rz90j4jssncm244bwdb"
    ],
    "name": "CVE-2026-42498",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-15T14:33:45Z",
    "bugzilla": {
      "description": "nginx: NGINX: Arbitrary code execution via crafted HTTP requests",
      "id": "2500967",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500967"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.\nImpact:\nThis vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.\n Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in NGINX. An unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP requests when the `map` directive uses regular expression (regex) matching and references regex capture variables before referencing the map output variable. This can lead to a heap buffer overflow, which may allow for arbitrary code execution on systems where Address Space Layout Randomization (ASLR) is disabled or bypassed. Additionally, this flaw can cause a denial-of-service (DoS) due to the NGINX worker process restarting."
    ],
    "statement": "This vulnerability in NGINX allows a remote, unauthenticated attacker to trigger a heap buffer overflow, leading to a denial of service (Dos). This occurs when the `map` directive uses regex matching and references regex capture variables before the map output variable. While arbitrary code execution is a theoretical risk, it is significantly reduced on Red Hat systems where Address Space Layout Randomization (ASLR) is enabled by default.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-26T00:00:00Z",
        "advisory": "RHSA-2026:46012",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nginx-main-1.30.4-2.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:10",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "nginx:1.24/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "nginx:1.24/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "nginx:1.26/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Lightspeed proxy 1",
        "fix_state": "Affected",
        "package_name": "insights-proxy/insights-proxy-container-rhel9",
        "cpe": "cpe:/a:redhat:insights_proxy:1",
        "impact": "moderate"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42533\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42533\nhttps://my.f5.com/manage/s/article/K000162097"
    ],
    "name": "CVE-2026-42533",
    "mitigation": {
      "value": "To mitigate this vulnerability, do not use unnamed captures. Use named captures instead and only use them in the same block with the regex match.\nRed Hat recommends updating nginx to the latest version when a fix is available.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-08T15:14:49Z",
    "bugzilla": {
      "description": "httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue",
      "id": "2486406",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486406"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-22",
    "details": [
      "A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.\nUsers are recommended to upgrade to version 2.4.68, which fixes this issue.",
      "A flaw was found in the `mod_dav_fs` module of Apache HTTP Server. A WebDAV (Web Distributed Authoring and Versioning) content author could exploit a path handling issue to directly manipulate trusted DAV property databases. This manipulation could potentially lead to child process crashes, resulting in a Denial of Service (DoS)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34109",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41906",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.5"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25042",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.68-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "httpd:2.4/httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Affected",
        "package_name": "jbcs-httpd24-httpd",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Affected",
        "package_name": "mod_dav_fs.so",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42535\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42535\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-42535",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-08T15:23:46Z",
    "bugzilla": {
      "description": "httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc",
      "id": "2486411",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486411"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
      "A flaw was found in Apache HTTP Server, specifically within the mod_xml2enc module. This heap-based buffer overflow vulnerability can be triggered when processing untrusted content through the xml2StartParse function. A remote attacker could potentially exploit this to cause a denial of service, information disclosure, or possibly arbitrary code execution."
    ],
    "statement": "In Red Hat Enterprise Linux (RHEL), the httpd package includes mod_xml2enc, which provides encoding support for filters like mod_proxy_html. Because this flaw relies on processing unvetted or untrusted input text lengths, the impact presents a high risk to availability (Denial of Service via worker crashes) and a potential risk to confidentiality if an attacker is capable of executing remote code within the context of the apache or httpd daemon process.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34109",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47046",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "httpd-0:2.4.63-1.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42828",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "httpd:2.4-8100020260714175253.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41906",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.5"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25042",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.68-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Affected",
        "package_name": "jbcs-httpd24-httpd",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42536\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42536\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-42536",
    "mitigation": {
      "value": "To mitigate this vulnerability, disable the `mod_xml2enc` module if its functionality for XML internationalization is not essential. This can be done by commenting out the `LoadModule xml2enc_module modules/mod_xml2enc.so` directive in the Apache HTTP Server configuration. A service restart is required for the change to take effect.\n```bash\n# Edit the Apache configuration file, e.g., /etc/httpd/conf.modules.d/00-base.conf\n# Comment out the line:\n# LoadModule xml2enc_module modules/mod_xml2enc.so\n# Reload the httpd service\nsudo systemctl reload httpd\n```\n*Note: Disabling `mod_xml2enc` will cause any configurations relying heavily on `mod_proxy_html` or raw HTML/XML encoding conversions to function incorrectly or fail. Red Hat strongly recommends upgrading to a patched version of `httpd` as soon as it becomes available for your specific RHEL channel.*",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Synopsis"
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42616\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42616"
    ],
    "name": "CVE-2026-42616",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Synopsis"
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42617\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42617"
    ],
    "name": "CVE-2026-42617",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Synopsis"
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42618\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42618"
    ],
    "name": "CVE-2026-42618",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-09T00:00:00Z",
    "bugzilla": {
      "description": "openssl: Possible NULL Dereference in Password-Based CMS Decryption",
      "id": "2481890",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\nApplications that process password-encrypted CMS messages may be affected.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "A flaw was found in OpenSSL. A remote attacker could exploit a NULL pointer dereference vulnerability in the Cryptographic Message Syntax (CMS) decryption process by providing a specially crafted password-encrypted CMS message. This occurs because the keyDerivationAlgorithm field, which is optional, is dereferenced without proper validation. Successful exploitation leads to an application crash, resulting in a Denial of Service."
    ],
    "statement": "This issue is rated as Low impact. A NULL pointer dereference in OpenSSL's CMS decryption can be triggered by a specially crafted password-encrypted CMS message, leading to an Red Hat application crash and Denial of Service. This affects applications that perform password-based CMS decryption.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25237",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "openssl-1:3.5.5-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25239",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25239",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-4.el9_8"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34102",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1782890503"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Under investigation",
        "package_name": "jbcs-httpd24-openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Under investigation",
        "package_name": "jbcs-openssl-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Under investigation",
        "package_name": "jws-optional-native-components-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7",
        "fix_state": "Under investigation",
        "package_name": "jws-optional-native-components-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42766\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42766"
    ],
    "name": "CVE-2026-42766",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-09T00:00:00Z",
    "bugzilla": {
      "description": "openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()",
      "id": "2481892",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-205",
    "details": [
      "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to\nBleichenbacher-style attack when an attacker is able to provide the CMS or\nS/MIME messages and observe the error code and/or decryption output.\nImpact summary: The Bleichenbacher-style attack allows an attacker to use the\nvictim's vulnerable application as a way to decrypt or sign messages with the\nvictim's private RSA key.\nThe attack is possible in 2 variants.\n1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without\nproviding the recipient certificate. In this case OpenSSL iterates over every\nKeyTransRecipientInfo (KTRI) without stopping at the first success.\nAn attacker who authors a message with two KTRI entries — the first one\nwrapping a real CEK under the victim's public key, the second with an\narbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to\nget a valid PKCS#1 v1.5 padding if the error code of the application is\navailable.\nThat is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an\nadaptive-chosen-ciphertext side channel from which the attacker decrypts any\nRSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under\nit.\n2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with\nthe recipient certificate, and the recipient is not found, a random\nkey is substituted.\nAn attacker who authors a message and is able to compare both error code and\nthe result of the decryption, can mount a Bleichenbacher oracle.\nWe are not aware of any applications that provide a remote attacker\nan opportunity to mount an attack described in these scenarios. We consider\nthe existence of such application very unlikely, and for this reason this\nCVE has been evaluated as Low severity.\nTo avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the\ninvoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described\nin draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit\nrejection was explicitly disabled.\nThe implicit rejection mechanism always returns a plaintext value,\nthe symmetric key. This result is deterministic for the ciphertext and the\nprivate key.  The length of the decryption result can happen to match the\nlength of the key of the symmetric cipher that was used for the content\nencryption. When a certificate is not provided, the last RecipientInfo\nproducing a key that looks valid will be used. It may cause getting garbage\ncontent on decryption. As a proper way to deal with this a recipient\ncertificate has to be provided to identify the particular RecipientInfo for\ndecryption.\nThe FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as\nCMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
      "A flaw was found in OpenSSL's CMS_decrypt() and PKCS7_decrypt() functions. This vulnerability, a Bleichenbacher-style oracle, could allow a remote attacker to decrypt or sign messages using the victim's private RSA key. Exploitation requires the attacker to provide specially crafted CMS or S/MIME messages and observe the application's error codes or decryption output. While the attack is technically possible, the specific conditions required make it unlikely to be exploited in typical deployments."
    ],
    "statement": "This Low severity vulnerability in OpenSSL's CMS_decrypt() and PKCS7_decrypt() functions exposes a Bleichenbacher-style oracle. Exploitation requires an attacker to control input CMS/S/MIME messages and observe decryption errors or output, a scenario deemed unlikely in most Red Hat product deployments. The attack could allow decryption or signing of messages with a victim's private RSA key.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25237",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "openssl-1:3.5.5-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25239",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25239",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-4.el9_8"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34102",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1782890503"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Under investigation",
        "package_name": "jbcs-httpd24-openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Under investigation",
        "package_name": "jbcs-openssl-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Under investigation",
        "package_name": "jws-optional-native-components-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7",
        "fix_state": "Under investigation",
        "package_name": "jws-optional-native-components-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42768\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42768"
    ],
    "name": "CVE-2026-42768",
    "mitigation": {
      "value": "To mitigate this vulnerability, applications utilizing CMS_decrypt() or PKCS7_decrypt() should ensure a recipient certificate is always provided to identify the specific RecipientInfo for decryption. This practice helps prevent the Bleichenbacher-style oracle attack by ensuring proper key identification.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-07T14:22:25Z",
    "bugzilla": {
      "description": "Django: Django: Privilege Abuse via Forged POST Data in GenericInlineModelAdmin",
      "id": "2455939",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455939"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-639",
    "details": [
      "An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.\nAdd permissions on inline model instances were not validated on submission of\nforged `POST` data in `GenericInlineModelAdmin`.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank N05ec@LZU-DSLab for reporting this issue.",
      "A flaw was found in Django. This vulnerability allows an attacker to bypass permission validation by submitting forged `POST` data to the `GenericInlineModelAdmin` component. As a result, unauthorized inline model instances could be added, potentially leading to privilege abuse or unauthorized data manipulation within the application."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/automation-reports",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/discovery-server",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/iop-advisor-backend-sat-6-18",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4277\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4277\nhttps://docs.djangoproject.com/en/dev/releases/security/\nhttps://github.com/django/django/commit/ef8b25dcc06d158683a5623ce406d561638f4073\nhttps://groups.google.com/g/django-announce\nhttps://www.djangoproject.com/weblog/2026/apr/07/security-releases/"
    ],
    "name": "CVE-2026-4277",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-05-01T10:01:10Z",
    "bugzilla": {
      "description": "Apache MINA: deserialization of untrusted data (incomplete fix for CVE-2026-41409)",
      "id": "2464321",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464321"
    },
    "cvss3": {
      "cvss3_base_score": "9.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-502",
    "details": [
      "The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:\nThe fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.\nAffected versions are Apache MINA 2.1.0 <= 2.1.11, and 2.2.0 <= 2.2.6.\nThe problem is resolved in Apache MINA 2.1.12, and 2.2.7 by \napplying the classname allowlist earlier.\nAffected are applications using Apache MINA that call IoBuffer.getObject().\nApplications using Apache MINA are advised to upgrade\nThe fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.\nAffected versions are Apache MINA 2.1.0 <= 2.1.110, and 2.2.0 <= 2.2.6.\nThe problem is resolved in Apache MINA 2.1.12, and 2.2.7 by \napplying the classname allowlist earlier.\nAffected are applications using Apache MINA that call IoBuffer.getObject().\nApplications using Apache MINA are advised to upgrade",
      "A flaw was found in Apache MINA. An incomplete fix for a deserialization issue in the `AbstractIoBuffer.getObject()` method allowed a static initializer in a class to be executed before the classname allowlist was applied. This vulnerability allows a remote attacker to execute arbitrary code in applications calling the `IoBuffer.getObject()` method."
    ],
    "statement": "Red Hat products are affected by this vulnerability. However, the vulnerable code cannot be reached and therefore are not vulnerable. Due to this reason, this flaw has been rated with a low severity.",
    "package_state": [
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "jenkins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "jenkins-2-plugins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "Red Hat AMQ Broker 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:amq_broker:7"
      },
      {
        "product_name": "Red Hat build of Apache Camel for Spring Boot 4",
        "fix_state": "Fix deferred",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:camel_spring_boot:4"
      },
      {
        "product_name": "Red Hat Data Grid 8",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_data_grid:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "javapackages-tools:201801/maven-wagon",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "maven:3.9/maven-wagon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "maven-wagon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Fuse 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_fuse:7"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform 8",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jbosseapxp"
      },
      {
        "product_name": "Red Hat Process Automation 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
      },
      {
        "product_name": "Red Hat Single Sign-On 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
      },
      {
        "product_name": "streams for Apache Kafka 2",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:amq_streams:2"
      },
      {
        "product_name": "streams for Apache Kafka 3",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:amq_streams:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42778\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42778\nhttps://lists.apache.org/thread/fhlx5k91hrkgyzh7yk1nghrn3k27gxy0"
    ],
    "name": "CVE-2026-42778",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-05-01T10:00:43Z",
    "bugzilla": {
      "description": "Apache MINA: Apache MINA: Arbitrary Code Execution via Classname Allowlist Bypass",
      "id": "2464322",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464322"
    },
    "cvss3": {
      "cvss3_base_score": "9.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-502",
    "details": [
      "The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:\nApache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed.\nThe fix checks if the class is present in the accepted class filter before calling Class.forName(). \nAffected versions are Apache MINA 2.1.0 <= 2.1.11, and 2.2.0 <= 2.2.6.\nThe problem is resolved in Apache MINA 2.1.12, and 2.2.7 by \napplying the classname allowlist earlier.\nAffected are applications using Apache MINA that call  IoBuffer.getObject().\nApplications using Apache MINA are advised to upgrade.",
      "A flaw was found in Apache MINA. An attacker can exploit a vulnerability in the AbstractIoBuffer.resolveClass() method, specifically when IoBuffer.getObject() is called, to bypass the classname allowlist. This bypass allows for the execution of arbitrary code, potentially leading to full system compromise."
    ],
    "statement": "Red Hat products are affected by this vulnerability. However, the vulnerable code cannot be reached and therefore are not vulnerable. Due to this reason, this flaw has been rated with a low severity.",
    "package_state": [
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "jenkins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "jenkins-2-plugins",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "Red Hat AMQ Broker 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:amq_broker:7"
      },
      {
        "product_name": "Red Hat build of Apache Camel for Spring Boot 4",
        "fix_state": "Fix deferred",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:camel_spring_boot:4"
      },
      {
        "product_name": "Red Hat Data Grid 8",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_data_grid:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "javapackages-tools:201801/maven-wagon",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "maven:3.9/maven-wagon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "maven-wagon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Fuse 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_fuse:7"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform 8",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jbosseapxp"
      },
      {
        "product_name": "Red Hat Process Automation 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
      },
      {
        "product_name": "Red Hat Single Sign-On 7",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
      },
      {
        "product_name": "streams for Apache Kafka 2",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:amq_streams:2"
      },
      {
        "product_name": "streams for Apache Kafka 3",
        "fix_state": "Not affected",
        "package_name": "mina-core",
        "cpe": "cpe:/a:redhat:amq_streams:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42779\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42779\nhttps://lists.apache.org/thread/fhlx5k91hrkgyzh7yk1nghrn3k27gxy0"
    ],
    "name": "CVE-2026-42779",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-07T14:22:38Z",
    "bugzilla": {
      "description": "Django: Django: Unauthorized instance creation via forged POST data in Admin changelist forms",
      "id": "2455941",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455941"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-472",
    "details": [
      "An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.\nAdmin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new\ninstances to be created via forged `POST` data.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Cantina for reporting this issue.",
      "A flaw was found in Django. Admin changelist forms utilizing `ModelAdmin.list_editable` were susceptible to improper access control. A remote attacker could exploit this by sending forged `POST` data, leading to the unauthorized creation of new instances within the application."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/automation-reports",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/discovery-server",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "redhat-user-workloads/iop-advisor-backend-sat-6-18",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4292\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4292\nhttps://docs.djangoproject.com/en/dev/releases/security/\nhttps://groups.google.com/g/django-announce\nhttps://www.djangoproject.com/weblog/2026/apr/07/security-releases/"
    ],
    "name": "CVE-2026-4292",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-13T14:12:44Z",
    "bugzilla": {
      "description": "nginx: ngx_http_charset_module: information disclosure and denial of service",
      "id": "2477066",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477066"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-126",
    "details": [
      "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering (\"off\") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.\n Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in the ngx_http_charset_module module of NGINX. When charset, source_charset, charset_map and proxy_pass with disabled buffering (\"off\") directives are configured, an unauthenticated attacker can send crafted requests and cause a heap-based buffer over-read in the worker process, resulting in a limited disclosure of memory or a denial of service by forcing the process to restart."
    ],
    "statement": "To exploit this vulnerability, the charset, source_charset, charset_map and proxy_pass directives must be configured with disabled buffering, limiting its exposure as this is not the default configuration. Also, configurations that do not recode a UTF-8 response through charset_map are not vulnerable. This issue allows an attacker to have limited control to disclose memory content from the worker process or cause a denial of service by forcing the process to restart, but it cannot cause a complete system denial of service. Due to these reasons, this flaw has been rated with a moderate severity.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Out of support scope",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nginx:1.24/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nginx:1.24/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nginx:1.26/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "nginx",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Lightspeed proxy 1",
        "fix_state": "Fix deferred",
        "package_name": "insights-proxy/insights-proxy-container-rhel9",
        "cpe": "cpe:/a:redhat:insights_proxy:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42934\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42934\nhttps://my.f5.com/manage/s/article/K000161028"
    ],
    "name": "CVE-2026-42934",
    "mitigation": {
      "value": "To mitigate this vulnerability, enable proxy buffering (the default configuration).",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Critical",
    "public_date": "2026-05-13T14:12:43Z",
    "bugzilla": {
      "description": "nginx: NGINX: Arbitrary Code Execution Vulnerability",
      "id": "2477116",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477116"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests under specific rewrite configurations. This can lead to a heap buffer overflow in the NGINX worker process, which may result in arbitrary code execution if Address Space Layout Randomization (ASLR), a security technique to prevent exploitation, is disabled. Otherwise, this flaw causes a denial of service due to a restart of the NGINX worker process."
    ],
    "statement": "Critical: This flaw in NGINX's ngx_http_rewrite_module can lead to arbitrary code execution due to a heap buffer overflow if Address Space Layout Randomization (ASLR) is disabled, or a denial of service otherwise. Exploitation requires specific, non-default NGINX rewrite configurations involving unnamed PCRE captures and a question mark in the replacement string.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18063",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "nginx-2:1.26.3-2.el10_1.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19159",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "nginx-2:1.26.3-6.el10_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-15T00:00:00Z",
        "advisory": "RHSA-2026:17790",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "nginx-2:1.26.3-1.el10_0.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18041",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nginx:1.24-8100020260514165201.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-18T00:00:00Z",
        "advisory": "RHSA-2026:18029",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx-2:1.20.1-24.el9_7.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19371",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.24-9080020260514160836.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19372",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.26-9080020260514152324.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19374",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx-2:1.20.1-28.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-15T00:00:00Z",
        "advisory": "RHSA-2026:17791",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "nginx-1:1.20.1-10.el9_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-15T00:00:00Z",
        "advisory": "RHSA-2026:17751",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "nginx-1:1.20.1-14.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-15T00:00:00Z",
        "advisory": "RHSA-2026:17792",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nginx-1:1.20.1-16.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-15T00:00:00Z",
        "advisory": "RHSA-2026:17793",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "nginx:1.24-9040020260514192210.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-15T00:00:00Z",
        "advisory": "RHSA-2026:17752",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx:1.24-9060020260514175739.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-15T00:00:00Z",
        "advisory": "RHSA-2026:17753",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx:1.26-9060020260514170123.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-15T00:00:00Z",
        "advisory": "RHSA-2026:17794",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "nginx-2:1.20.1-22.el9_6.6"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17417",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nginx-main-1.30.1-1.hum1"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.14",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22396",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.14::el9",
        "package": "odf4/ocs-client-console-rhel9:1779972138"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.14",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22396",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.14::el9",
        "package": "odf4/odf-console-rhel9:1779972283"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.14",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22396",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.14::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1779972179"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.15",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22393",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.15::el9",
        "package": "odf4/ocs-client-console-rhel9:1779967811"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.15",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22393",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.15::el9",
        "package": "odf4/odf-console-rhel9:1779967813"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.15",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22393",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.15::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1779968303"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.16",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22394",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
        "package": "odf4/ocs-client-console-rhel9:1779959318"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.16",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22394",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
        "package": "odf4/odf-console-rhel9:1779959527"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.16",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22394",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1779959592"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22390",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/ocs-client-console-rhel9:1779952245"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22390",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/odf-console-rhel9:1779952279"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.17",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22390",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1779952463"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22388",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-console-rhel9:1779881302"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22388",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-console-rhel9:1779881608"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22388",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1779881122"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22389",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-console-rhel9:1779881012"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22389",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-console-rhel9:1779881008"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22389",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1779881332"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22383",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-client-console-rhel9:1779879463"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22383",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-console-rhel9:1779877770"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22383",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1779881377"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22382",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/ocs-client-console-rhel9:1779946521"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22382",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-console-rhel9:1779946525"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.21",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22382",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.21::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1779946691"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-05-25T00:00:00Z",
        "advisory": "RHSA-2026:20442",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/iop-gateway-rhel9:1779706745"
      },
      {
        "product_name": "Red Hat Satellite 6.19",
        "release_date": "2026-05-25T00:00:00Z",
        "advisory": "RHSA-2026:20444",
        "cpe": "cpe:/a:redhat:satellite:6.19::el9",
        "package": "satellite/iop-gateway-rhel9:1779706797"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1779798159"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat 3scale API Management Platform 2",
        "fix_state": "Affected",
        "package_name": "3scale-amp2/apicast-gateway-rhel8",
        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
      },
      {
        "product_name": "Red Hat Lightspeed proxy 1",
        "fix_state": "Affected",
        "package_name": "insights-proxy/insights-proxy-container-rhel9",
        "cpe": "cpe:/a:redhat:insights_proxy:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42945\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42945\nhttps://depthfirst.com/nginx-rift\nhttps://my.f5.com/manage/s/article/K000161019"
    ],
    "csaw": true,
    "name": "CVE-2026-42945"
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-13T14:12:44Z",
    "bugzilla": {
      "description": "nginx: ngx_http_scgi_module: ngx_http_uwsgi_module: information disclosure and denial of service",
      "id": "2477132",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477132"
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-823",
    "details": [
      "A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in the ngx_http_scgi_module and ngx_http_uwsgi_module modules of NGINX. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker able to intercept and modify network traffic via a Man-In-The-Middle (MITM) attack and control the responses from an upstream server may be able to read sensitive data from the worker process or cause a denial of service by forcing the process to restart."
    ],
    "statement": "To exploit this issue, an attacker needs to be able to control the responses from SCGI or uWSGI backend servers via a Man-In-The-Middle (MITM) attack, limiting its exposure. Also, this vulnerability allows an attacker to read sensitive data from the memory of the worker process or cause a denial of service by forcing the process to restart, but it cannot cause a complete system denial of service. Due to these reasons, this flaw has been rated with a moderate severity.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nginx:1.24/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nginx:1.24/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nginx:1.26/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "nginx",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Lightspeed proxy 1",
        "fix_state": "Fix deferred",
        "package_name": "insights-proxy/insights-proxy-container-rhel9",
        "cpe": "cpe:/a:redhat:insights_proxy:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-42946\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42946\nhttps://my.f5.com/manage/s/article/K000161027"
    ],
    "name": "CVE-2026-42946",
    "mitigation": {
      "value": "To mitigate this flaw, ensure that the connection between NGINX and the backend SCGI/uWSGI servers is fully encrypted and authenticated, preventing the interception and manipulation of responses required to exploit this vulnerability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "public_date": "2026-05-06T00:00:00Z",
    "bugzilla": {
      "description": "kernel: fbdev: vt8500lcdfb: fix missing dma_free_coherent()",
      "id": "2467069",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467069"
    },
    "cwe": "CWE-772",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nfbdev: vt8500lcdfb: fix missing dma_free_coherent()\nfbi->fb.screen_buffer is allocated with dma_alloc_coherent() but is not\nfreed if the error path is reached.",
      "A flaw was found in the Linux kernel's `fbdev: vt8500lcdfb` module. This vulnerability, a memory leak, occurs because allocated memory is not properly freed when an error path is triggered. A local attacker could potentially exploit this to exhaust system resources, leading to a Denial of Service (DoS)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43202\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43202\nhttps://lore.kernel.org/linux-cve-announce/2026050646-CVE-2026-43202-2ab9@gregkh/T"
    ],
    "name": "CVE-2026-43202",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-06T00:00:00Z",
    "bugzilla": {
      "description": "kernel: net/rds: No shortcut out of RDS_CONN_ERROR",
      "id": "2467167",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467167"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-372",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nnet/rds: No shortcut out of RDS_CONN_ERROR\nRDS connections carry a state \"rds_conn_path::cp_state\"\nand transitions from one state to another and are conditional\nupon an expected state: \"rds_conn_path_transition.\"\nThere is one exception to this conditionality, which is\n\"RDS_CONN_ERROR\" that can be enforced by \"rds_conn_path_drop\"\nregardless of what state the condition is currently in.\nBut as soon as a connection enters state \"RDS_CONN_ERROR\",\nthe connection handling code expects it to go through the\nshutdown-path.\nThe RDS/TCP multipath changes added a shortcut out of\n\"RDS_CONN_ERROR\" straight back to \"RDS_CONN_CONNECTING\"\nvia \"rds_tcp_accept_one_path\" (e.g. after \"rds_tcp_state_change\").\nA subsequent \"rds_tcp_reset_callbacks\" can then transition\nthe state to \"RDS_CONN_RESETTING\" with a shutdown-worker queued.\nThat'll trip up \"rds_conn_init_shutdown\", which was\nnever adjusted to handle \"RDS_CONN_RESETTING\" and subsequently\ndrops the connection with the dreaded \"DR_INV_CONN_STATE\",\nwhich leaves \"RDS_SHUTDOWN_WORK_QUEUED\" on forever.\nSo we do two things here:\na) Don't shortcut \"RDS_CONN_ERROR\", but take the longer\npath through the shutdown code.\nb) Add \"RDS_CONN_RESETTING\" to the expected states in\n\"rds_conn_init_shutdown\" so that we won't error out\nand get stuck, if we ever hit weird state transitions\nlike this again.\"",
      "A flaw was found in the Linux kernel's Reliable Datagram Sockets (RDS) component. Due to an incorrect state transition, an RDS connection can bypass its expected shutdown process. This can lead to the connection becoming permanently stuck in a shutdown-queued state, potentially causing a denial of service by preventing further connection handling."
    ],
    "statement": "Red Hat acknowledges the upstream Linux kernel correction for «net/rds» as described in COMMENT_ZERO. Fixes are delivered through standard kernel errata for supported products. Operational exposure depends on whether this subsystem or driver is active in your configuration.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43226\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43226\nhttps://lore.kernel.org/linux-cve-announce/2026050654-CVE-2026-43226-496c@gregkh/T"
    ],
    "name": "CVE-2026-43226",
    "mitigation": {
      "value": "To mitigate this issue, prevent the rds module from being loaded. See https://access.redhat.com/solutions/41278 for instructions.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-12T15:24:02Z",
    "bugzilla": {
      "description": "tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication",
      "id": "2476511",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476511"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-303",
    "details": [
      "DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0.\nOlder unsupported versions any also be affect\nUsers are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.",
      "A flaw was found in Apache Tomcat. When DIGEST authentication was configured, any user not known to the configured Realm would be authenticated if they presented the password \"null\". This allows a remote attacker to bypass security controls."
    ],
    "statement": "This Moderate flaw in Apache Tomcat allows an authentication bypass when DIGEST authentication is configured. An attacker can authenticate as any unknown user by providing the password 'null', potentially gaining unauthorized access to applications protected by DIGEST authentication. Red Hat products are only affected if they are configured to use DIGEST authentication, which is not a common, out of the box and expected configuration for Production environments. \nFurthermore, because the unknown user is not mapped to any valid realm roles, their access is still restricted by standard application authorization constraints, significantly limiting the actual impact.\nThe unknown user is not mapped to any existing user, which means, it does not steal credentials nor impersonate an existing user. This new user is expected to have the minimum possible authentication and authorization range within the realm inherited roles.",
    "affected_release": [
      {
        "product_name": "Red Hat JBoss Web Server 6.2.4",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43402",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2",
        "package": "tomcat-coyote"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 10",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 8",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el9jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0.0",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39189",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
        "package": "tomcat-coyote"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 10",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 8",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 9",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el9jws"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13745",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.22-0.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16528",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.55-1.hum1"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces 3.28",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25123",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3.28::el9",
        "package": "devspaces/server-rhel9:1780694994"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Certificate System 10",
        "fix_state": "Not affected",
        "package_name": "redhat-pki:10/jss",
        "cpe": "cpe:/a:redhat:certificate_system:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "jss",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "mod_proxy_cluster",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Under investigation",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "jss",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "mod_proxy_cluster",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Fuse 7",
        "fix_state": "Will not fix",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jboss_fuse:7"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-mod_cluster-native",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-mod_proxy_cluster",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
        "fix_state": "Not affected",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jbosseapxp"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Not affected",
        "package_name": "jws5-mod_cluster",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Will not fix",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Not affected",
        "package_name": "jws6-mod_cluster",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat Process Automation 7",
        "fix_state": "Will not fix",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
      },
      {
        "product_name": "Red Hat Single Sign-On 7",
        "fix_state": "Not affected",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43512\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43512\nhttps://lists.apache.org/thread/7x09x7o12solvclslw3sz0288xc8wx73"
    ],
    "name": "CVE-2026-43512",
    "mitigation": {
      "value": "To mitigate this issue, disable DIGEST authentication within Apache Tomcat if it is not essential for your environment. This involves modifying the server's authentication configuration to utilize alternative methods or remove the DIGEST realm. A service restart is required for these changes to take effect and may impact functionality relying on DIGEST authentication.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-12T15:26:25Z",
    "bugzilla": {
      "description": "tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm",
      "id": "2476520",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476520"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-178",
    "details": [
      "Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.\nOlder unsupported versions may also be affected.\nUsers are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.",
      "In Apache Tomcat, LockOutRealm mishandled case sensitivity in usernames, resulting in less effective blocking of brute force attacks."
    ],
    "statement": "A flaw was found in Apache Tomcat's LockOutRealm. When configured with an underlying Realm where usernames are case-insensitive, the LockOutRealm does not account for case differences, potentially reducing the effectiveness of brute-force protection. Exploitation requires LockOutRealm to be configured with a case-insensitive authentication backend, which is a non-default configuration.",
    "affected_release": [
      {
        "product_name": "Red Hat JBoss Web Server 6.2.4",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43402",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2",
        "package": "tomcat-catalina"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 10",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 8",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el9jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0.0",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39189",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
        "package": "tomcat-catalina"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 10",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 8",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 9",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el9jws"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44426",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.57-3.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44427",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.24-0.2.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43513\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43513\nhttps://lists.apache.org/thread/ytjcgldshj73lcnd1sh95od5hrghwogp"
    ],
    "name": "CVE-2026-43513",
    "mitigation": {
      "value": "This vulnerability only affects Tomcat deployments using the LockOutRealm with a case-insensitive authentication backend. Deployments not using LockOutRealm or using case-sensitive authentication backends are not affected.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-05-12T15:32:09Z",
    "bugzilla": {
      "description": "tomcat-coyote: Apache Tomcat: Information disclosure via AJP secret timing discrepancy",
      "id": "2476512",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476512"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-208",
    "details": [
      "Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.\nOlder unsupported versions may also be affected.\nUsers are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.",
      "A flaw was found in Apache Tomcat. The AJP secret was comparable in non-constant time, allowing an attacker on the local network to mount a timing attack to determine the AJP secret, which may lead to unauthorized access or other security bypasses."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat JBoss Web Server 6.2.4",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43402",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2",
        "package": "tomcat-coyote"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 10",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 8",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el9jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0.0",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39189",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
        "package": "tomcat-coyote"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 10",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 8",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 9",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el9jws"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13745",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.22-0.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16528",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.55-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Certificate System 10",
        "fix_state": "Fix deferred",
        "package_name": "redhat-pki:10/jss",
        "cpe": "cpe:/a:redhat:certificate_system:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jss",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "mod_proxy_cluster",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jss",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mod_proxy_cluster",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Fuse 7",
        "fix_state": "Out of support scope",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jboss_fuse:7"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "jbcs-httpd24-mod_cluster-native",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "jbcs-httpd24-mod_proxy_cluster",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
        "fix_state": "Out of support scope",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jbosseapxp"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Out of support scope",
        "package_name": "jws5-mod_cluster",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Out of support scope",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Fix deferred",
        "package_name": "jws6-mod_cluster",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Process Automation 7",
        "fix_state": "Out of support scope",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
      },
      {
        "product_name": "Red Hat Single Sign-On 7",
        "fix_state": "Out of support scope",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43514\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43514\nhttps://lists.apache.org/thread/2k654v5cq123npfsd1b2kk1y30owqb1m"
    ],
    "name": "CVE-2026-43514",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-12T15:33:23Z",
    "bugzilla": {
      "description": "tomcat-coyote: tomcat: Improper Authorization allows security bypass",
      "id": "2476519",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476519"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-551",
    "details": [
      "Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.\nUsers are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.",
      "In Apache Tomcat, when multiple security constraints defined an HTTP method constraint for the same extension pattern, only the first method constraint was applied. A remote attacker could exploit this to bypass intended security restrictions for information or actions within the application."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat JBoss Web Server 6.2.4",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43402",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2",
        "package": "tomcat-coyote"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 10",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 8",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el9jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0.0",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39189",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
        "package": "tomcat-coyote"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 10",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 8",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 9",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el9jws"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13745",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.22-0.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16528",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.55-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Certificate System 10",
        "fix_state": "Fix deferred",
        "package_name": "redhat-pki:10/jss",
        "cpe": "cpe:/a:redhat:certificate_system:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Will not fix",
        "package_name": "jss",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "mod_proxy_cluster",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "jss",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "mod_proxy_cluster",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Fuse 7",
        "fix_state": "Will not fix",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jboss_fuse:7"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-mod_cluster-native",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-mod_proxy_cluster",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
        "fix_state": "Not affected",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jbosseapxp"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Not affected",
        "package_name": "jws5-mod_cluster",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Will not fix",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Not affected",
        "package_name": "jws6-mod_cluster",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7",
        "fix_state": "Not affected",
        "package_name": "jws7-mod_cluster",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Process Automation 7",
        "fix_state": "Will not fix",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
      },
      {
        "product_name": "Red Hat Single Sign-On 7",
        "fix_state": "Will not fix",
        "package_name": "tomcat-coyote",
        "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43515\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43515\nhttps://lists.apache.org/thread/746nxfxod0wsocxtmv8pb8nkgmwpc6bb"
    ],
    "name": "CVE-2026-43515",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-17T19:42:03Z",
    "bugzilla": {
      "description": "mongo-c-driver: mongo-c-driver: Denial of Service via malformed HTTP response",
      "id": "2448447",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448447"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-170",
    "details": [
      "A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.",
      "A flaw was found in mongo-c-driver. A compromised third-party cloud server or a man-in-the-middle (MITM) attacker could send a malformed HTTP response. This could cause applications using the MongoDB C driver to crash, leading to a Denial of Service."
    ],
    "statement": "This LOW impact vulnerability in the MongoDB C driver allows denial of service via malformed HTTP responses. Exploitation requires high complexity—either a compromised cloud server or active MITM position. Impact is limited to availability. Applications are only vulnerable when connecting to untrusted MongoDB instances or over untrusted networks.",
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4359\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4359\nhttps://jira.mongodb.org/browse/CDRIVER-6251"
    ],
    "name": "CVE-2026-4359",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-21T13:26:00Z",
    "bugzilla": {
      "description": "libXpm: libXpm: Denial of Service via out-of-bounds read in XPM file parsing",
      "id": "2448984",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448984"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.",
      "A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions."
    ],
    "statement": "The vulnerability is assessed as Medium severity due to its impact being limited to availability. While exploitation requires local access and low privileges, it does not require user interaction. Successful exploitation can cause applications processing XPM files to crash, which may affect batch processing systems or graphical applications. The absence of confidentiality and integrity impact reduces the overall severity, but the ease of triggering the issue still presents a reliability concern.",
    "acknowledgement": "Red Hat would like to thank Naoki Wakamatsu (JPCERT/CC Vulnerability Coordination Group) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-26T00:00:00Z",
        "advisory": "RHSA-2026:30354",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libxpm-main-3.5.17-7.2.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47072",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libxpm-main-3.5.19-4.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libXpm",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "libXpm",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libXpm",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libXpm",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libXpm",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4367\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4367\nhttps://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/5448e1bd\nhttps://seclists.org/oss-sec/2026/q2/192"
    ],
    "name": "CVE-2026-4367",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-05-04T05:41:07Z",
    "bugzilla": {
      "description": "mutt: Mutt: Low integrity impact in IMAP authentication due to cryptographic digest mishandling",
      "id": "2464857",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464857"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-303",
    "details": [
      "mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.",
      "A flaw was found in mutt, an email client, where it mishandles cryptographic digests used for IMAP (Internet Message Access Protocol) authentication. This incorrect handling could lead to a low integrity impact, potentially allowing a remote attacker to subtly affect the authentication process."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43859\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43859\nhttps://github.com/muttmua/mutt/commit/834c5a2ed0479e51e8662a31caed129f136f4805"
    ],
    "name": "CVE-2026-43859",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-05-04T05:45:05Z",
    "bugzilla": {
      "description": "mutt: mutt: Authentication bypass due to IMAP CRAM-MD5 hash truncation",
      "id": "2464859",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464859"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-193",
    "details": [
      "mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.",
      "A flaw was found in mutt. During the IMAP CRAM-MD5 (Challenge-Response Authentication Mechanism - Message-Digest Algorithm 5) authentication, the password hash is truncated by one byte. This issue could allow a remote attacker to potentially bypass authentication, leading to unauthorized access."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43860\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43860\nhttps://github.com/muttmua/mutt/commit/834c5a2ed0479e51e8662a31caed129f136f4805"
    ],
    "name": "CVE-2026-43860",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-05-04T05:52:59Z",
    "bugzilla": {
      "description": "mutt: Mutt: URL processing vulnerability due to improper null character handling",
      "id": "2464868",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464868"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-170",
    "details": [
      "mutt before 2.3.2 does not check for '\\0' in url_pct_decode.",
      "A flaw was found in mutt, an email client. The `url_pct_decode` function, which is responsible for decoding URL-encoded strings, does not correctly handle null termination characters. This vulnerability could allow a remote attacker, to manipulate how URLs are processed, potentially leading to a limited loss of data integrity."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Out of support scope",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43861\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43861\nhttps://github.com/muttmua/mutt/commit/12f54fe3b61f761c096fe95e95d5e3072af00ed2"
    ],
    "name": "CVE-2026-43861",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-05-04T06:00:46Z",
    "bugzilla": {
      "description": "mutt: Mutt: Security bypass due to mishandled IMAP authentication",
      "id": "2464861",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464861"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-843",
    "details": [
      "In mutt before 2.3.2, the imap_auth_gss security level is mishandled.",
      "A flaw was found in mutt, an email client. The `imap_auth_gss` security level, which is used for secure IMAP (Internet Message Access Protocol) authentication, is mishandled. This vulnerability could allow an attacker to bypass certain security protections, potentially leading to a low impact on data integrity."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43862\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43862\nhttps://github.com/muttmua/mutt/commit/f547a849cdacb512800a5f477c27de217e1c8151"
    ],
    "name": "CVE-2026-43862",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-05-04T06:05:53Z",
    "bugzilla": {
      "description": "mutt: Mutt: Remote Denial of Service via crafted input",
      "id": "2464865",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464865"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-835",
    "details": [
      "mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.",
      "A flaw was found in mutt, an email client. A remote attacker could exploit this vulnerability by sending specially crafted input, which would trigger an infinite loop in the `data_object_to_stream` function. This issue, located in the `crypt-gpgme.c` component, can lead to a Denial of Service (DoS), causing the application to become unresponsive."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43863\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43863\nhttps://github.com/muttmua/mutt/commit/fdc04a171777327218a1e78db504926c388b48c4"
    ],
    "name": "CVE-2026-43863",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-04T06:10:52Z",
    "bugzilla": {
      "description": "mutt: Mutt: Denial of Service via null pointer dereference in show_sig_summary",
      "id": "2464862",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464862"
    },
    "cvss3": {
      "cvss3_base_score": "4.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-476",
    "details": [
      "mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.",
      "A flaw was found in mutt. This vulnerability, a null pointer dereference in the `show_sig_summary` function, could allow an attacker to cause a denial of service. This occurs when processing specially crafted input related to signature summaries."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "mutt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43864\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43864\nhttps://github.com/muttmua/mutt/commit/ebfa2969042d89303d15334193fcc32866c8a8df"
    ],
    "name": "CVE-2026-43864",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-11T17:20:06Z",
    "bugzilla": {
      "description": "jq: jq: Arbitrary Code Execution or Denial of Service via Signed Integer Overflow",
      "id": "2469175",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2469175"
    },
    "cvss3": {
      "cvss3_base_score": "6.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).",
      "A flaw was found in jq, a tool used for processing JSON data from the command line. A remote attacker can exploit a vulnerability by providing a specially crafted large number as input. This can cause an internal calculation error, leading to a memory overflow where the attacker can write their own data into the system's memory, potentially resulting in the application crashing (Denial of Service)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29986",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Out of support scope",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43894\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43894\nhttps://github.com/jqlang/jq/security/advisories/GHSA-5v7p-2r57-2g4g"
    ],
    "name": "CVE-2026-43894",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-11T17:24:02Z",
    "bugzilla": {
      "description": "jq: embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts",
      "id": "2469199",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2469199"
    },
    "cvss3": {
      "cvss3_base_score": "4.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-20",
    "details": [
      "jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.",
      "A flaw was found in jq, a command line JSON processor. Embedded NUL bytes in import paths are truncated during module and data-file lookup, creating a mismatch between the intended import string and the actual file path opened. This issue allows an attacker who can supply a crafted script to access unintended files."
    ],
    "statement": "To exploit this flaw, an attacker needs to supply a crafted script containing embedded NUL bytes in import paths to be processed by jq. This allows the attacker to bypass intended path validation mechanisms and access unintended files. Due to these reasons, this issue has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29986",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43895\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43895\nhttps://github.com/jqlang/jq/security/advisories/GHSA-7q7g-mrq3-phxr"
    ],
    "name": "CVE-2026-43895",
    "mitigation": {
      "value": "Do not process untrusted scripts with the jq command line JSON processor.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-11T17:24:48Z",
    "bugzilla": {
      "description": "jq: stack overflow in recursive object merge",
      "id": "2469184",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2469184"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-674",
    "details": [
      "jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.",
      "A flaw was found in jq, a command line JSON processor. The `jv_object_merge_recursive` function, reachable via the `*` operator when both operands are objects, does not have a depth limit when processing nested objects. This missing depth limit allows an attacker who can supply a sufficiently nested input structure to exhaust the stack memory, causing an application crash and resulting in a denial of service."
    ],
    "statement": "To exploit this issue, an attacker needs to supply a crafted JSON input to be processed by jq with the `jv_object_merge_recursive` function, reachable via the `*` operator when both operands are objects. This allows the attacker to cause an application crash with no other security impact. Due to these reasons, this vulnerability has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29986",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Out of support scope",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43896\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43896\nhttps://github.com/jqlang/jq/security/advisories/GHSA-mg96-6h3q-g846"
    ],
    "name": "CVE-2026-43896",
    "mitigation": {
      "value": "Do not process untrusted input with the jq command line JSON processor.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-08T15:16:14Z",
    "bugzilla": {
      "description": "httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime",
      "id": "2486415",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486415"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.",
      "A flaw was found in Apache HTTP Server. An out-of-bounds read vulnerability exists when `mod_headers` and `mod_mime` are used with multiple response languages. This could allow a remote attacker to disclose sensitive information from memory or cause a denial of service."
    ],
    "statement": "This Moderate impact vulnerability in Apache HTTP Server arises from an out-of-bounds read when both `mod_headers` and `mod_mime` modules are active and configured for multiple response languages. While this configuration is not universally enabled by default in Red Hat products, affected systems could be vulnerable to information disclosure or denial of service if these specific modules and language settings are in use. Exploitation requires a remote attacker to trigger this specific module interaction.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34109",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34355",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mod_http2-0:2.0.29-4.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50538",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "mod_http2-0:2.0.29-2.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42828",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "httpd:2.4-8100020260714175253.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41906",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:55930",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "mod_http2-0:1.15.19-4.el9_2.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:55992",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "mod_http2-0:2.0.26-2.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50572",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "mod_http2-0:2.0.26-4.el9_6.2"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25042",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.68-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "mod_http2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "jbcs-httpd24-mod_http2",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "mod_http2.so",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43951\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43951\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-43951",
    "mitigation": {
      "value": "- Those who do not require multi-language response headers can remove or disable the `mod_headers` and `mod_mime` modules, or remove Content-Language directives from their configuration. \n- Systems not using these modules in combination are not affected.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-19T13:26:06Z",
    "bugzilla": {
      "description": "vim: Vimscript injection via unescaped filename in netrw s:NetrwMarkFile() filter() expression allows arbitrary code execution",
      "id": "2460434",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460434"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-94",
    "details": [
      "A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.",
      "A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim."
    ],
    "statement": "Important: This Vimscript injection flaw in netrw allows arbitrary code execution with user privileges. Exploitation requires a local attacker to place a specially crafted filename in a directory and a victim to browse that directory with netrw and interact with the malicious entry. This directly impacts the confidentiality, integrity, and availability of the user's data and environment.",
    "acknowledgement": "Red Hat would like to thank AISLE Research for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Under investigation",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Under investigation",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43961\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43961\nhttps://github.com/vim/vim/security/advisories/GHSA-66hr-7p6x-x5j3"
    ],
    "name": "CVE-2026-43961",
    "mitigation": {
      "value": "To mitigate this issue, users should avoid browsing untrusted directories or interacting with files from untrusted sources using Vim's netrw plugin. Exercise caution when opening directories that may contain maliciously crafted filenames.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-04T18:10:10Z",
    "bugzilla": {
      "description": "postfix: buffer over-read via malformed enhanced status code",
      "id": "2466488",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466488"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-193",
    "details": [
      "Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.",
      "A flaw was found in Postfix. This issue occurs when processing enhanced status codes, specifically an enhanced status code that lacks text following the third number. Depending on the configuration of the server, this allows a remote attacker to cause a buffer over-read of only 1 byte, leading to an application crash and resulting in a denial of service."
    ],
    "statement": "This vulnerability cannot be triggered with an SMTP or LMTP server response. Instead, it is exposed only under specific server configurations:\n- Access tables\n- Policy server responses\n- Pipe-to-command output, header_checks, body_checks, an error transport in transport_maps or a milter response\n- DNSBL server TXT responses (specifically when Postfix is configured with \"$rbl_code $rbl_text\" in rbl_reply_maps or default_rbl_reply)\nAs this flaw allows a remote attacker to cause a denial of service, it has been rated with an important severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25930",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "postfix-2:3.8.5-10.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51436",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "postfix-2:3.8.5-8.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57174",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "postfix-2:2.10.1-9.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25932",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "postfix-2:3.5.8-8.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25932",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "postfix-2:3.5.8-8.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51034",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "postfix-2:3.5.8-1.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51034",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "postfix-2:3.5.8-1.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:50963",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "postfix-2:3.5.8-4.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:50963",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "postfix-2:3.5.8-4.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:50964",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "postfix-2:3.5.8-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:50964",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "postfix-2:3.5.8-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26205",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "postfix-2:3.5.25-3.el9_8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "postfix",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-43964\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43964\nhttps://www.mail-archive.com/postfix-announce@postfix.org/msg00110.html"
    ],
    "name": "CVE-2026-43964",
    "mitigation": {
      "value": "To mitigate this vulnerability, review and adjust the following Postfix configurations:\n- DNSBL: Remove the $rbl_text variable from the rbl_reply_maps and default_rbl_reply settings to prevent triggers via malicious DNSBL TXT responses.\n- Policy Servers and Milters: Ensure any connected policy daemons or milters return fully RFC-compliant enhanced status codes. They must not return codes that lack text after the third digit (e.g., they should return 5.7.1 Rejected rather than just 5.7.1).\n- Access Tables and Content Checks: Audit custom access tables, header_checks, body_checks, and transport_maps (specifically error transports) to confirm that any manually defined rejection messages or status codes include descriptive text following the numeric code.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-08T15:17:31Z",
    "bugzilla": {
      "description": "httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges",
      "id": "2486416",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486416"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-266",
    "details": [
      "Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.\nThis issue affects Apache HTTP Server: from through 2.4.67.\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
      "A flaw was found in Apache HTTP Server. This improper privilege management vulnerability allows local .htaccess authors to read files with the privileges of the httpd user. This could lead to unauthorized information disclosure."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34109",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41906",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.5"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25042",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.68-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "httpd:2.4/httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "jbcs-httpd24-httpd",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44119\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44119\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-44119",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-12T17:34:04Z",
    "bugzilla": {
      "description": "mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()",
      "id": "2488459",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488459"
    },
    "cvss3": {
      "cvss3_base_score": "9.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-89",
    "details": [
      "MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.",
      "A flaw was found in MariaDB server. An application processing non-validated user input, which then uses `mysql_real_escape_string()` and sends data to the database via text protocol with the big5 character set, is vulnerable to SQL injection. This allows a remote attacker to execute malicious SQL commands, potentially leading to unauthorized data access or modification within the database."
    ],
    "statement": "This is an Important SQL injection vulnerability in MariaDB server affecting applications that utilize `mysql_real_escape_string()` with non-validated user input and the `big5` character set. Exploitation allows a remote attacker to execute arbitrary SQL commands, potentially compromising data integrity and confidentiality within the database. The specific configuration required for exploitation limits its widespread impact, but systems configured in this manner are at significant risk.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43505",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mariadb-connector-c-0:3.4.4-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47772",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "mariadb-connector-c-0:3.4.4-1.el10_0.1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30135",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "mariadb-connector-c-main-3.4.9-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "mariadb10.11",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "mariadb11.8",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "mariadb",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "mariadb:10.11/mariadb",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "mariadb:10.3/mariadb",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "mariadb-connector-c",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "mariadb",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "mariadb:10.11/mariadb",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "mariadb:11.8/mariadb",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "mariadb-connector-c",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "mariadb10.11",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "mariadb11.8",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44172\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44172\nhttps://github.com/MariaDB/server/security/advisories/GHSA-pv9p-5w55-55jm\nhttps://jira.mariadb.org/browse/CONC-819"
    ],
    "name": "CVE-2026-44172",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-08T15:11:12Z",
    "bugzilla": {
      "description": "httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server",
      "id": "2486402",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486402"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-835",
    "details": [
      "Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.\nThis issue affects undefined: from 2.4.0 through 2.4.67.\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
      "A flaw was found in the `mod_proxy_ftp` module of the Apache HTTP Server. A remote attacker, by controlling a backend File Transfer Protocol (FTP) server, can trigger an infinite loop. This vulnerability, categorized as a Loop with Unreachable Exit Condition, leads to a Denial of Service (DoS) for the affected server."
    ],
    "statement": "A loop with an unreachable exit condition flaw was found in the mod_proxy_ftp module of the Apache HTTP Server. A remote attacker could exploit this vulnerability by tricking the server into connecting to a malicious or compromised backend FTP server, causing the proxy_ftp_handler component to enter an infinite loop. This results in CPU exhaustion and a denial of service (DoS) condition on the affected system.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34109",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42828",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "httpd:2.4-8100020260714175253.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41906",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.5"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25042",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.68-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Affected",
        "package_name": "jbcs-httpd24-httpd",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44186\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44186\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-44186",
    "mitigation": {
      "value": "To mitigate this issue, you can disable the `mod_proxy_ftp` module if your environment does not require it.\n#### **Step 1: Disable the Module**\nOpen your Apache HTTP Server configuration file (commonly located at `/etc/httpd/conf.modules.d/00-proxy.conf` or `/etc/httpd/conf/httpd.conf`) and comment out or remove the following line:\n```\n# LoadModule proxy_ftp_module modules/mod_proxy_ftp.so\n```\n#### **Step 2: Restart the Service**\nRestart the `httpd` service to apply the configuration changes:\n```\nsystemctl restart httpd\n```\n**Note:** Disabling this module may impact applications or services that rely on Apache's FTP proxy functionality.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-30T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Synopsis"
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44235\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44235"
    ],
    "name": "CVE-2026-44235",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-30T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Synopsis"
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44236\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44236"
    ],
    "name": "CVE-2026-44236",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-19T00:00:00Z",
    "bugzilla": {
      "description": "libarchive: libarchive: Denial of Service via malformed ISO file processing",
      "id": "2449010",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449010"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1335",
    "details": [
      "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.",
      "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition."
    ],
    "statement": "This MODERATE impact vulnerability in `libarchive`'s zisofs decompression logic can lead to a denial of service. The flaw is triggered when processing a specially crafted ISO9660 image containing an invalid shift exponent. Red Hat products that process untrusted ISO files using `libarchive` are susceptible to crashes.",
    "acknowledgement": "Red Hat would like to thank Elhanan Haenel for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8944",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libarchive-main-3.8.7-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4426\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4426\nhttps://github.com/libarchive/libarchive/pull/2897"
    ],
    "name": "CVE-2026-4426",
    "mitigation": {
      "value": "To mitigate this issue, avoid processing untrusted ISO9660 images with `libarchive`. Restricting the sources of ISO files and ensuring they originate from trusted entities can prevent exploitation.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-12T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted domain name that is accessed in a reverse DNS lookup. When \"UseReverseDNS on\" is enabled, the attacker-supplied hostname is passed unescaped into SQL queries. The character restrictions of DNS names may affect exploitability."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44331\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44331"
    ],
    "name": "CVE-2026-44331",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-13T15:20:24Z",
    "bugzilla": {
      "description": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers",
      "id": "2477167",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477167"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-201",
    "details": [
      "urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.",
      "A flaw was found in urllib3, an HTTP client library for Python. When using the low-level API via `ProxyManager.connection_from_url().urlopen()` with `assert_same_host=False`, cross-origin redirects can still forward sensitive headers. This could allow a remote attacker to gain unauthorized access to sensitive information."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34160",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "python3.12-urllib3-0:2.7.0-1.el9ap"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27929",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "python3.14-urllib3-0:2.6.3-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:28000",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "python-urllib3-0:1.26.19-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32992",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python3.12-urllib3-0:1.26.19-3.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:49927",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "fence-agents-0:4.2.1-129.el8_10.28"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:47126",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::highavailability",
        "package": "resource-agents-0:4.9.0-54.el8_10.36"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36732",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "python-urllib3-0:1.24.2-10.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51152",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "fence-agents-0:4.2.1-65.el8_4.31"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47091",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4::highavailability",
        "package": "resource-agents-0:4.1.1-90.el8_4.26"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51152",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "fence-agents-0:4.2.1-65.el8_4.31"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47091",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4::highavailability",
        "package": "resource-agents-0:4.1.1-90.el8_4.26"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51157",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "fence-agents-0:4.2.1-89.el8_6.25"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51157",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "fence-agents-0:4.2.1-89.el8_6.25"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47092",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6::highavailability",
        "package": "resource-agents-0:4.9.0-16.el8_6.23"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51045",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "fence-agents-0:4.2.1-112.el8_8.20"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:47129",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8::highavailability",
        "package": "resource-agents-0:4.9.0-40.el8_8.20"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51045",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "fence-agents-0:4.2.1-112.el8_8.20"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:47129",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8::highavailability",
        "package": "resource-agents-0:4.9.0-40.el8_8.20"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28157",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.14-urllib3-0:2.6.3-2.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28159",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.12-urllib3-0:1.26.19-3.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28158",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "python-urllib3-0:1.26.5-8.el9_8"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30078",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1782352950"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30087",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1782352919"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30088",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782353093"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30089",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1782352847"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.4",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24540",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.4::el9",
        "package": "rhaii/vllm-cpu-rhel9:1780356811"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.4",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24541",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.4::el9",
        "package": "rhaii/vllm-spyre-rhel9:1780356904"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.4",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24542",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.4::el9",
        "package": "rhaii/model-opt-cuda-rhel9:1780356941"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.4",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24544",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.4::el9",
        "package": "rhaii/vllm-cuda-rhel9:1780356914"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42144",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "ansible-automation-platform-25/hub-rhel8:1784050598"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34374",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/gateway-rhel9:1782761510"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34374",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-chatbot-rhel9:1782650747"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42132",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/controller-rhel9:1783973764"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42132",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/de-minimal-rhel9:1783921549"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42132",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/de-supported-rhel9:1783923629"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42132",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-tech-preview/metrics-service-rhel9:1783969139"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.7",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25928",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.7::el9",
        "package": "ansible-automation-platform-27/hub-rhel9:1781102816"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33313",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782756541"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-07T00:00:00Z",
        "advisory": "RHSA-2026:24009",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python-urllib3-main-2.7.0-3.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25039",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jaeger-main-2.19.0-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30169",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python-sentry-sdk-main-2.48.0-6.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34119",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python-rpds-py-main-2026.6.3-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37094",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "mariadb11-8-main-11.8.8-3.hum1"
      },
      {
        "product_name": "Red Hat Migration Toolkit for Applications 8.2",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:43038",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8.2::el9",
        "package": "mta/mta-solution-server-rhel9:1784109883"
      },
      {
        "product_name": "Red Hat Migration Toolkit for Applications 8.2",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56347",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8.2::el9",
        "package": "mta/mta-rhel9-operator:1786481481"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-caikit-tgis-serving-rhel9:1783082430"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-kserve-storage-initializer-rhel9:1783024305"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-llama-stack-core-rhel9:1783701598"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-modelmesh-runtime-adapter-rhel9:1783342900"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-ta-lmes-job-rhel9:1783091175"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-vllm-cuda-rhel9:1783998774"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-vllm-rocm-rhel9:1783998857"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-kserve-storage-initializer-rhel9:1783010225"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-mlflow-rhel9:1782917849"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-mlserver-rhel9:1782887848"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-cuda121-torch24-py311-rhel9:1782471555"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-cuda124-torch25-py311-rhel9:1782471579"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-cuda128-torch28-py312-rhel9:1783073038"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-cuda128-torch29-py312-rhel9:1782991170"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-rocm62-torch24-py311-rhel9:1782471656"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-rocm62-torch25-py311-rhel9:1782471663"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-rocm64-torch28-py312-rhel9:1783069204"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-rocm64-torch29-py312-rhel9:1782991170"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9:1782472374"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9:1782471606"
      },
      {
        "product_name": "Red Hat Satellite 6.17",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44696",
        "cpe": "cpe:/a:redhat:satellite:6.17::el9",
        "package": "satellite/iop-advisor-engine-rhel9:1784834402"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26212",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/iop-puptoo-rhel9:1779792651"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26215",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/iop-yuptoo-rhel9:1779792968"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26221",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/iop-vmaas-rhel9:1780392987"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26226",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/iop-host-inventory-rhel9:1780414237"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26304",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/iop-insights-engine-rhel9:1779711334"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36350",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/foreman-mcp-server-rhel9:1782739344"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51356",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/iop-advisor-backend-rhel9:1784558256"
      },
      {
        "product_name": "Red Hat Satellite 6.18",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51357",
        "cpe": "cpe:/a:redhat:satellite:6.18::el9",
        "package": "satellite/iop-vulnerability-engine-rhel9:1784554123"
      },
      {
        "product_name": "Red Hat Satellite 6.19",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34526",
        "cpe": "cpe:/a:redhat:satellite:6.19::el9",
        "package": "satellite/iop-vmaas-rhel9:1782139619"
      },
      {
        "product_name": "Red Hat Satellite 6.19",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34531",
        "cpe": "cpe:/a:redhat:satellite:6.19::el9",
        "package": "satellite/iop-puptoo-rhel9:1780393451"
      },
      {
        "product_name": "Red Hat Satellite 6.19",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34532",
        "cpe": "cpe:/a:redhat:satellite:6.19::el9",
        "package": "satellite/iop-host-inventory-rhel9:1780403026"
      },
      {
        "product_name": "Red Hat Satellite 6.19",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34533",
        "cpe": "cpe:/a:redhat:satellite:6.19::el9",
        "package": "satellite/iop-yuptoo-rhel9:1782380482"
      },
      {
        "product_name": "Red Hat Satellite 6.19",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34607",
        "cpe": "cpe:/a:redhat:satellite:6.19::el9",
        "package": "satellite/iop-insights-engine-rhel9:1782448455"
      },
      {
        "product_name": "Red Hat Satellite 6.19",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51206",
        "cpe": "cpe:/a:redhat:satellite:6.19::el9",
        "package": "satellite/iop-advisor-backend-rhel9:1784558259"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.4",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24483",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.4::el9",
        "package": "rhtas/model-transparency-rhel9:1780914886"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1784794818"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1784794778"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1784795112"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1784794289"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1784795076"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Out of support scope",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/bitwarden-sdk-server-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-operator-bundle",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-operator-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-rhel8-operator",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Fix deferred",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Will not fix",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Will not fix",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:0"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Not affected",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:1"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python-urllib3",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat build of Quarkus Native builder",
        "fix_state": "Not affected",
        "package_name": "urllib3",
        "cpe": "cpe:/a:redhat:quarkus:3"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Will not fix",
        "package_name": "rhdh/rhdh-hub-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Not affected",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "python3.14-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "python-urllib3",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Will not fix",
        "package_name": "python-s3transfer",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "python-urllib3",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python3.11-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python3.11-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python3.14-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/disk-image-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "llvm",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "llvm21",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-attrs",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-cryptography",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-trustme",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Affected",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "trivy",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-built-in-detector-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-caikit-nlp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-guardrails-detector-huggingface-runtime-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llm-d-inference-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Out of support scope",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/rhai-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-catalogd-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ztp-site-generate-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/hyperconverged-cluster-operator-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Out of support scope",
        "package_name": "container-native-virtualization/hyperconverged-cluster-webhook-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "python-urllib3",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Out of support scope",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "python-urllib3",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite-capsule:el8/python-urllib3",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Out of support scope",
        "package_name": "rhtas/segment-reporting-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 4 for Cloud Providers",
        "fix_state": "Not affected",
        "package_name": "python-urllib3",
        "cpe": "cpe:/a:redhat:rhui:4::el8"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Affected",
        "package_name": "stf/service-telemetry-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Affected",
        "package_name": "stf/smart-gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44431\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44431\nhttps://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc"
    ],
    "name": "CVE-2026-44431",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-05-28T00:00:00Z",
    "bugzilla": {
      "description": "rpm: heap buffer overflow in NDB slot table parsing",
      "id": "2482481",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482481"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.",
      "A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable."
    ],
    "statement": "This vulnerability has a Low impact on Red Hat Enterprise Linux and Fedora systems. A heap buffer overflow in RPM's NDB database backend can be triggered by processing a specially crafted NDB database file. However, NDB is not the default RPM database backend in these distributions, which instead utilize SQLite, significantly reducing the attack surface.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33507",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "rpm-main-6.0.1-6.2.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "rpm",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "rust-bootupd",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Under investigation",
        "package_name": "rpm",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Under investigation",
        "package_name": "rpm",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "rpm",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "rpm",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "rust-bootupd",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44605\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44605"
    ],
    "name": "CVE-2026-44605",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-22T13:06:28Z",
    "bugzilla": {
      "description": "libunbound: libunbound: Denial of Service via specially crafted network traffic",
      "id": "2506149",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506149"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-617",
    "details": [
      "With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function is absent from the function call allow list. When an application using libunbound sets 'unwanted-reply-threshold' to any non-zero value and the iterator queries an authoritative that replies with enough wrong-transaction-ID UDP datagrams to cross the threshold, the 'libworker_alloc_cleanup' will eventually be called. Since the function is absent from the function call allow list, this leads to a fatal exit of libunbound and eventual termination of the embedding application.Unbound itself is not affected since its relevant function 'worker_alloc_cleanup' is registed in the allow list and proceeds to perform the documented cache flush.",
      "A flaw was found in libunbound, a library used by applications for DNS resolution. A remote attacker could exploit this vulnerability by sending specially crafted network traffic. This could cause applications using libunbound to terminate unexpectedly, leading to a denial of service (DoS). This occurs when the 'unwanted-reply-threshold' is configured, and the application attempts to call a cleanup function that is not properly allowed, resulting in a fatal exit."
    ],
    "statement": "A Moderate denial of service flaw exists in `libunbound` where applications configured with `unwanted-reply-threshold` can be terminated by specially crafted network traffic. This occurs when the `libworker_alloc_cleanup` function is called, which is not on the allow list for embedded applications. The `unbound` daemon itself is not affected as it uses a different, allowed function.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "unbound",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44621\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44621\nhttps://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44621.txt"
    ],
    "name": "CVE-2026-44621",
    "mitigation": {
      "value": "To mitigate this issue, ensure that any applications using `libunbound` do not set the `unwanted-reply-threshold` to a non-zero value. Disabling or setting this threshold to zero prevents the vulnerable code path from being triggered.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-08T15:19:23Z",
    "bugzilla": {
      "description": "httpd: Apache HTTP Server: Denial of Service via crafted regular expressions",
      "id": "2486399",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486399"
    },
    "cvss3": {
      "cvss3_base_score": "7.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-124",
    "details": [
      "Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
      "A flaw was found in Apache HTTP Server. This buffer underwrite vulnerability occurs when processing crafted regular expressions in the server's configuration. An attacker could potentially exploit this to cause a denial of service."
    ],
    "statement": "This Moderate impact buffer underwrite flaw in Apache HTTP Server can lead to a denial of service. The vulnerability occurs when processing specially crafted regular expressions within the server's configuration. Exploitation requires a high attack complexity, indicating that specific conditions or a complex attack vector are necessary, thereby limiting the practical risk in typical Red Hat deployments where configuration changes are tightly controlled.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34109",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "httpd-0:2.4.63-13.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47046",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "httpd-0:2.4.63-1.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42828",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "httpd:2.4-8100020260714175253.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41906",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "httpd-0:2.4.62-13.el9_8.5"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25042",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.68-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "httpd",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Affected",
        "package_name": "jbcs-httpd24-httpd",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44631\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44631\nhttps://httpd.apache.org/security/vulnerabilities_24.html"
    ],
    "name": "CVE-2026-44631",
    "mitigation": {
      "value": "Only loadtrustedApache configuration; the bug triggers oncrafted regexin config at start/reload (DirectoryMatch,Directory ~,ProxyMatch, etc.).\nKeep AllowOverride None where possible so untrusted users cannot inject regex via .htaccess.\nRestrict who can change httpdconfig and reload the service.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-08T22:40:49Z",
    "bugzilla": {
      "description": "vim: Vim: Arbitrary command execution via :find command-line completion",
      "id": "2468420",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468420"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "status": "draft"
    },
    "cwe": "CWE-78",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435.",
      "A flaw was found in Vim, an open-source command-line text editor. An attacker who controls the contents of a file can exploit an OS command injection vulnerability in Vim's `:find` command-line completion. This occurs when the `path` option, which can be set from a modeline, contains backtick-enclosed shell commands. These commands are then executed when a user opens the malicious file and triggers `:find` completion, leading to arbitrary command execution."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44656\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44656\nhttps://github.com/vim/vim/commit/190cb3c2b9c769a3972bcfd991a7b5b6cb771ef0\nhttps://github.com/vim/vim/releases/tag/v9.2.0435\nhttps://github.com/vim/vim/security/advisories/GHSA-hwg5-3cxw-wvvg"
    ],
    "name": "CVE-2026-44656",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-22T00:00:00Z",
    "bugzilla": {
      "description": "unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes",
      "id": "2503063",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503063"
    },
    "cvss3": {
      "cvss3_base_score": "8.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
      "status": "verified"
    },
    "details": [
      "In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.",
      "A flaw was found in Unbound. Insufficient validation of the RRSIG.Labels field, combined with premature cache writes during RFC 8198 aggressive NSEC processing, can lead to cache poisoning. This vulnerability allows a malicious actor, controlling a single delegated zone, to poison arbitrary sibling zones under NSEC-signed parent domains. The primary impact is the integrity of DNS resolution, potentially leading to users being directed to malicious websites or services."
    ],
    "statement": "This Important flaw in Unbound allows a remote attacker to perform DNS cache poisoning. By controlling a delegated zone, a malicious actor can manipulate DNS resolution for arbitrary sibling zones under NSEC-signed parent domains, potentially redirecting users to malicious destinations. This poses a significant integrity risk to systems relying on Unbound for DNS resolution.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55892",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "unbound-0:1.24.2-7.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55784",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "unbound-0:1.16.2-5.14.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55841",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "unbound-0:1.24.2-3.el9_8.4"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43588",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "unbound-main-1.25.2-0.1.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44690\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44690"
    ],
    "name": "CVE-2026-44690",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-11T17:23:20Z",
    "bugzilla": {
      "description": "jq: stack overflow in module loading on mutual include",
      "id": "2469192",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2469192"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-674",
    "details": [
      "jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other.",
      "A flaw was found in jq, a command line JSON processor. The module loader fails to perform cycle detection when resolving imports. This missing cycle detection allows an attacker who can supply crafted modules with circular dependencies to exhaust the stack memory, causing an application crash, resulting in a denial of service."
    ],
    "statement": "To exploit this vulnerability, an attacker needs to supply crafted modules with circular dependencies to be processed by the jq module loader. This allows the attacker to cause an application crash with no other security impact. Due to these reasons, this issue has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29986",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Out of support scope",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44777\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44777\nhttps://github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9"
    ],
    "name": "CVE-2026-44777",
    "mitigation": {
      "value": "Do not process untrusted input with the jq command line JSON processor.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-22T21:30:11Z",
    "bugzilla": {
      "description": "webob: python-webob: WebOb: Open Redirect vulnerability via HTTP Location header normalization",
      "id": "2491570",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491570"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-601",
    "details": [
      "WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit strips ASCII tab, carriage return, and newline characters before parsing, so a redirect target containing such characters can be reinterpreted as a protocol-relative URL whose authority is an attacker-controlled host. This bypasses the CVE-2024-42353 fix that escaped a leading double slash, allowing an attacker who influences the redirect location to send users to an arbitrary external site instead of the intended one. This vulnerability is fixed in 1.8.10.",
      "A flaw was found in WebOb, a library for HTTP requests and responses. A remote attacker could exploit this vulnerability by influencing the HTTP Location header during a redirect. Due to improper normalization of the Location header, specifically how certain ASCII characters are handled, an attacker can cause a user to be redirected to an arbitrary external website instead of the intended destination. This open redirect vulnerability can lead to information disclosure and impact the integrity of user sessions."
    ],
    "statement": "This is rated as Moderate (CVSS 6.1) because exploitation requires user interaction — a victim must click a crafted link that triggers the redirect (UI:R). While the attack is network-accessible (AV:N) and requires no privileges (PR:N), the impact is limited to low confidentiality and integrity effects typical of an open redirect (phishing, session misdirection), with no availability impact. Critically, this vulnerability is only exploitable on Python 3.10 or later, where urllib.parse.urlsplit strips tab, carriage return, and newline characters before parsing. All Red Hat product streams that ship python-webob — including Red Hat OpenShift Container Platform, Red Hat OpenStack Platform, Red Hat Ceph Storage, and Red Hat Quay — use Python 3.9 or earlier as the platform runtime, and are therefore not affected. Fedora and EPEL ship python-webob under Python 3.12+ and are affected. Users running WebOb on Python 3.10+ should upgrade to version 1.8.10, or validate that redirect targets include an explicit scheme with the expected host before assigning to Response.location.",
    "package_state": [
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Not affected",
        "package_name": "python-webob",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "python-webob",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "python-webob",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "python-webob",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "python-webob",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "python-webob",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "python-webob",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44889\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44889\nhttps://github.com/Pylons/webob/security/advisories/GHSA-fh3h-vg37-cc95"
    ],
    "name": "CVE-2026-44889",
    "mitigation": {
      "value": "This vulnerability in WebOb is only exploitable when running under Python 3.10 or later, where urllib.parse.urlsplit strips ASCII tab, carriage return, and newline characters before parsing. Red Hat Enterprise Linux, OpenShift Container Platform, Red Hat OpenStack Platform, Red Hat Ceph Storage, and Red Hat Quay all ship python-webob with Python 3.9 or earlier as the platform Python runtime, and are therefore not affected by this vulnerability. Fedora and EPEL ship python-webob under Python 3.12+, where the vulnerability is exploitable. Users running WebOb on Python 3.10+ should upgrade to WebOb 1.8.10. As a workaround, applications can validate that redirect targets start with a scheme (e.g. http:// or https://) and the expected host before assigning to Response.location.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-05-08T07:13:04Z",
    "bugzilla": {
      "description": "uriparser: uriparser: Data integrity issue due to pointer truncation",
      "id": "2467976",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467976"
    },
    "cvss3": {
      "cvss3_base_score": "2.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-681",
    "details": [
      "In uriparser before 1.0.2, there is pointer difference truncation to int in various places.",
      "A flaw was found in uriparser. This vulnerability involves pointer difference truncation, where calculations involving memory addresses are incorrectly shortened. This could lead to minor data integrity issues within the application. Exploitation of this flaw requires local access to the system and is complex."
    ],
    "statement": "This flaw in uriparser has a Low impact, as it requires local access to the system and is complex to exploit. The pointer difference truncation could lead to minor data integrity issues within applications utilizing uriparser.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16341",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "uriparser-main-1.0.2-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "uriparser",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "uriparser",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44927\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44927\nhttps://github.com/uriparser/uriparser/pull/304"
    ],
    "name": "CVE-2026-44927",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-08T07:15:28Z",
    "bugzilla": {
      "description": "uriparser: uriparser: Incorrect URI comparison leading to integrity issues",
      "id": "2467974",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467974"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-1025",
    "details": [
      "In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.",
      "A flaw was found in uriparser. The `EqualsUri` function can incorrectly identify distinct Uniform Resource Identifiers (URIs) as identical. This misclassification can lead to improper URI handling within applications that use uriparser, potentially compromising data integrity."
    ],
    "statement": "A Moderate integrity flaw was found in uriparser, where the `EqualsUri` function can incorrectly identify distinct URIs as identical. This misclassification can lead to improper URI handling within applications utilizing uriparser, potentially compromising data integrity in Red Hat products that rely on accurate URI differentiation.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16341",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "uriparser-main-1.0.2-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "uriparser",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "uriparser",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44928\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44928\nhttps://github.com/uriparser/uriparser/pull/305"
    ],
    "name": "CVE-2026-44928",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-05T10:00:00Z",
    "bugzilla": {
      "description": "libxfonts2: libXfont2: Privilege Escalation via Heap Buffer Overflow in Font Server Client",
      "id": "2509622",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509622"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "A flaw was found in the libXfont2 font-server client. This heap buffer overflow vulnerability allows a malicious font server to send specially crafted glyph data. The fs_read_glyphs() function fails to properly validate the total size of the incoming data, leading to an overwrite of memory beyond the intended buffer. If the X server runs as a privileged user, this could result in privilege escalation, allowing an attacker to gain higher access. If the X server runs as an unprivileged user, it could lead to a denial of service, causing the system to crash."
    ],
    "statement": "This is an Important flaw. A heap buffer overflow in the `libXfont2` font server client can be triggered by a malicious font server. If the X server runs as root, this could lead to privilege escalation; otherwise, it results in a denial of service. Red Hat Enterprise Linux typically runs the X server as an unprivileged user, mitigating the privilege escalation risk but still allowing for denial of service.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55448",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libXfont2-0:2.0.6-5.el10_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55446",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libXfont2-0:2.0.3-2.el8_10.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55447",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libXfont2-0:2.0.3-12.el9_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59311",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libXfont2-0:2.0.3-12.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59312",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "libXfont2-0:2.0.3-12.el9_4.3"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "libXfont2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-44950\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44950"
    ],
    "name": "CVE-2026-44950",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-10T21:25:20Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service due to resource policy bypass in PSD decoder",
      "id": "2487734",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487734"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a missing check in the PSD decoder it would be possible to bypass the list-length resource policy when decoding a PSD image. Other security limits would still apply. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.",
      "A flaw was found in ImageMagick. A missing check in the PSD (Photoshop Document) decoder allows an attacker to bypass the list-length resource policy when processing a specially crafted PSD image. This could lead to a denial of service (DoS) condition by consuming excessive resources."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32961",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "ImageMagick-0:6.9.10.68-17.el7_9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-45031\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-45031\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cwpj-h54c-xjpx"
    ],
    "name": "CVE-2026-45031",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-08T22:42:35Z",
    "bugzilla": {
      "description": "vim: Vim: Heap buffer overflow allows arbitrary code execution or denial of service",
      "id": "2468422",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468422"
    },
    "cvss3": {
      "cvss3_base_score": "6.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (.spl) with UTF-8 encoding active. An attacker-controlled length field in the spell file's compound section overflows a 32-bit signed integer multiplication, causing a small buffer to be allocated for a write loop that runs many iterations, overflowing the heap. Because the 'spelllang' option can be set from a modeline, a text file modeline can trigger spell file loading if a malicious .spl file has been planted on the runtimepath. This issue has been patched in version 9.2.0450.",
      "A flaw was found in Vim, an open-source command-line text editor. A heap buffer overflow exists in the `read_compound()` function when processing a specially crafted spell file (.spl) with UTF-8 encoding active. A remote attacker could exploit this by convincing a user to open a text file containing a malicious modeline, which could then load a planted malicious spell file. This could lead to a heap overflow, potentially resulting in an application-level denial of service."
    ],
    "statement": "This Moderate flaw in Vim arises from a heap buffer overflow when processing specially crafted spell files with UTF-8 encoding. Exploitation requires user interaction, specifically opening a text file containing a malicious modeline that points to a planted, malicious spell file. This limits the attack vector to scenarios where an attacker can control both the text file and the spell file on the user's system, leading primarily to application-level denial of service.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-45130\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-45130\nhttps://github.com/vim/vim/commit/92993329178cb1f72d700fff45ca86e1c2d369f8\nhttps://github.com/vim/vim/releases/tag/v9.2.0450\nhttps://github.com/vim/vim/security/advisories/GHSA-q4jv-r9gj-6cwv"
    ],
    "name": "CVE-2026-45130",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-10T06:36:16Z",
    "bugzilla": {
      "description": "libexpat: denial of service via crafted XML input",
      "id": "2468575",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468575"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-407",
    "details": [
      "In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.",
      "A flaw was found in libexpat. When processing a specially crafted XML input containing a specific pattern of attributes, the parsing time increases quadratically due to checks for attribute name collisions. This consumes excessive CPU resources and eventually results in a denial of service."
    ],
    "statement": "To exploit this issue, an attacker needs to be able to process a specially crafted XML file or input with an application linked to the libexpat library. Also, the only security impact of this flaw is a high consumption of CPU resources that can eventually cause a denial of service. Due to this reason, this vulnerability has been rated with an important severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22715",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "expat-0:2.7.3-1.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22721",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "expat-0:2.5.0-2.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23230",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "expat-0:2.5.0-6.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23230",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "expat-0:2.5.0-6.el9_8.1"
      },
      {
        "product_name": "Red Hat JBoss Core Services 2.4.62.SP4",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27201",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "libexpat-2.dll"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "compat-expat1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-45186\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-45186\nhttps://github.com/libexpat/libexpat/pull/1216"
    ],
    "name": "CVE-2026-45186",
    "mitigation": {
      "value": "To mitigate this vulnerability, restrict the maximum size of incoming XML payloads. It is especially critical to limit the decompressed size if the application accepts compressed XML files. Also, consider running the application inside a container or a restricted environment to ensure that the high consumption of CPU resources does not affect the host system.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-10T21:26:05Z",
    "bugzilla": {
      "description": "Magick.NET-Q16-AnyCPU: Magick.NET-Q16-HDRI-AnyCPU: Magick.NET-Q16-HDRI-OpenMP-arm64: Magick.NET-Q16-HDRI-OpenMP-x64: Magick.NET-Q16-HDRI-arm64: Magick.NET-Q16-HDRI-x64: Magick.NET-Q16-HDRI-x86: Magick.NET-Q16-OpenMP-arm64: Magick.NET-Q16-OpenMP-x64: Magick.NET-Q16-arm64: Magick.NET-Q16-x64: Magick.NET-Q16-x86: Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm64: Magick.NET-Q8-OpenMP-x64: Magick.NET-Q8-arm64: Magick.NET-Q8-x64: Magick.NET-Q8-x86: ImageMagick: Information disclosure due to an out-of-bounds read in the meta encoder",
      "id": "2487733",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487733"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-193",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, an off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.",
      "A flaw was found in ImageMagick, a free and open-source software for editing and manipulating digital images. A remote attacker could exploit an off-by-one error in the meta encoder to read a single byte outside of allocated memory. This out-of-bounds read could lead to the disclosure of sensitive information."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-45358\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-45358\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cr6r-hmj8-pr7r"
    ],
    "name": "CVE-2026-45358",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-03-22T05:35:12Z",
    "bugzilla": {
      "description": "pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer",
      "id": "2450066",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450066"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-1333",
    "details": [
      "A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
      "A flaw was found in pygments. A local user can exploit this vulnerability by providing specially crafted input to the AdlLexer function, which leads to inefficient regular expression processing. This can result in a Denial of Service (DoS), making the application unresponsive."
    ],
    "package_state": [
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/bitwarden-sdk-server-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-operator-bundle",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-operator-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Fix deferred",
        "package_name": "lightspeed-core/dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Fix deferred",
        "package_name": "lightspeed-core/lightspeed-stack-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Fix deferred",
        "package_name": "lightspeed-core/rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis-preview/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/ansible-dev-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/mcp-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform-tech-preview/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Not affected",
        "package_name": "rhdh/rhdh-hub-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python3.14-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python3.11-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "resource-agents",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python3.11-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.14-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/disk-image-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-nlp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-caikit-tgis-serving-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-rhel8",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda121-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda124-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda128-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda128-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-olm-catalogd-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/foreman-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-host-inventory-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-insights-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-puptoo-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vmaas-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vulnerability-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Out of support scope",
        "package_name": "rhtas/model-transparency-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4539\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4539\nhttps://github.com/pygments/pygments/\nhttps://github.com/pygments/pygments/issues/3058\nhttps://vuldb.com/?ctiid.352327\nhttps://vuldb.com/?id.352327\nhttps://vuldb.com/?submit.774685"
    ],
    "name": "CVE-2026-4539",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-05T22:06:07Z",
    "bugzilla": {
      "description": "python-idna: idna: Denial of Service via specially crafted long inputs",
      "id": "2485616",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485616"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the `idna.encode()` function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.",
      "A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications. A remote attacker could exploit this vulnerability by sending specially crafted, excessively long inputs to the library's encoding function. This could cause the system to consume significant resources, leading to a Denial of Service (DoS), where the affected application becomes unavailable to legitimate users. This issue stems from an incomplete fix for a previously identified vulnerability."
    ],
    "statement": "A flaw was found in the python-idna library. This is an incomplete fix for CVE-2024-3651. The idna.encode() function performs contextual validation checks (valid_contexto) before rejecting oversized inputs, allowing specially crafted long payloads to cause excessive CPU consumption and lead to a denial of service. The fix in version 3.14 rejects long inputs early before further processing, and version 3.15 extends this approach to alternate per-label conversion and codec functions.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54481",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "python-idna-0:3.7-6.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54290",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "python-idna-0:2.5-8.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54484",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "python-idna-0:2.10-8.el9_8"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25039",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jaeger-main-2.19.0-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-12T00:00:00Z",
        "advisory": "RHSA-2026:25503",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python-idna-main-3.18-1.hum1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34119",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python-rpds-py-main-2026.6.3-1.hum1"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9:1786705347"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/cephcsi-rhel9-operator:1786706101"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-core-rhel9:1786705558"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/mcg-rhel9-operator:1786705646"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-console-rhel9:1786706138"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-client-rhel9-operator:1786705741"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1786705777"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/ocs-rhel9-operator:1786705802"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cli-rhel9:1786705938"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-console-rhel9:1786706577"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1786706125"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1786706177"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1786706188"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1786706679"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1786706357"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-must-gather-rhel9:1786706612"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odf-rhel9-operator:1786706644"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/odr-rhel9-operator:1786706659"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.18",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56431",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1786706880"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Cluster Operator",
        "fix_state": "Fix deferred",
        "package_name": "confidential-clusters-beta/attestation-key-register-rhel9",
        "cpe": "cpe:/a:redhat:confidential_cluster_operator:4"
      },
      {
        "product_name": "Confidential Cluster Operator",
        "fix_state": "Not affected",
        "package_name": "confidential-clusters-beta/buildroot-rhel9",
        "cpe": "cpe:/a:redhat:confidential_cluster_operator:4"
      },
      {
        "product_name": "Confidential Cluster Operator",
        "fix_state": "Fix deferred",
        "package_name": "confidential-clusters-beta/compute-pcrs-rhel9",
        "cpe": "cpe:/a:redhat:confidential_cluster_operator:4"
      },
      {
        "product_name": "Confidential Cluster Operator",
        "fix_state": "Fix deferred",
        "package_name": "confidential-clusters-beta/confidential-cluster-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_cluster_operator:4"
      },
      {
        "product_name": "Confidential Cluster Operator",
        "fix_state": "Fix deferred",
        "package_name": "confidential-clusters-beta/confidential-cluster-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_cluster_operator:4"
      },
      {
        "product_name": "Confidential Cluster Operator",
        "fix_state": "Fix deferred",
        "package_name": "confidential-clusters-beta/registration-server-rhel9",
        "cpe": "cpe:/a:redhat:confidential_cluster_operator:4"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Fix deferred",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/bitwarden-sdk-server-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-operator-bundle",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-operator-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "External Secrets Operator for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "external-secrets-operator/external-secrets-rhel9",
        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Not affected",
        "package_name": "lightspeed-core/lightspeed-stack-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Fix deferred",
        "package_name": "mta/mta-dotnet-external-provider-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Fix deferred",
        "package_name": "mta/mta-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Fix deferred",
        "package_name": "mta/mta-solution-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Fix deferred",
        "package_name": "rhmtc/openshift-migration-rhel8-operator",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Fix deferred",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Fix deferred",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-agentic-sandbox-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-ztunnel-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Not affected",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:0"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Not affected",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:1"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "rhacm2/volsync-operator-bundle",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "rhacm2/volsync-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaii/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaii/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaii/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaii/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/mcp-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-operator-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/ansible-builder-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/mcp-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "python-idna",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform Ansible Core 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_core:2"
      },
      {
        "product_name": "Red Hat build of Quarkus Native builder",
        "fix_state": "Fix deferred",
        "package_name": "idna",
        "cpe": "cpe:/a:redhat:quarkus:3"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Not affected",
        "package_name": "rhcl-1/limitador-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Connectivity Link 1",
        "fix_state": "Not affected",
        "package_name": "rhcl-1/wasm-shim-rhel9",
        "cpe": "cpe:/a:redhat:connectivity_link:1"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Fix deferred",
        "package_name": "rhdh/rhdh-hub-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Fix deferred",
        "package_name": "rhdh/rhdh-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Not affected",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python3.14-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhel10-2-els/rhel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhel10-eus/rhel-10.0-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhel10-eus/rhel-10.2-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhel10/keylime-registrar",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhel10/keylime-verifier",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhel10/rhel-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "ubi10/toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "ubi10/ubi10",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "mozjs52",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python-idna",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "fence-agents",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "rhel8-4-els/rhel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "ubi8/toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "fence-agents",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.14-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9-2-els/rhel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9-8-els/rhel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9-eus/rhel-9.6-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9-eus/rhel-9.8-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/keylime-registrar",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/keylime-verifier",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/rhel-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ubi9/toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ubi9/ubi9",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "ubi9/ubi-stig",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/disk-image-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux command line assistant",
        "fix_state": "Not affected",
        "package_name": "rhel-cla/rhel-knowledge-bridge-rhel10",
        "cpe": "cpe:/a:redhat:rhel_cla:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "aardvark-dns",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "chunkah",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "llvm",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "llvm21",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "mariadb11.8",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "netavark",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-attrs",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-cryptography",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-jsonschema",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-sentry-sdk",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-trustme",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-urllib3",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "qt6-qtbase",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "ruby3.4",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "ruby4.0",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "ruff",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "rust-podman-sequoia",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "rust-rpm-sequoia",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "trivy",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-automl-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-autorag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-built-in-detector-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-caikit-nlp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-tgis-serving-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-fms-guardrails-orchestrator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-guardrails-detector-huggingface-runtime-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-autogluon-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llm-d-inference-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llm-d-kv-cache-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlserver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipelines-components-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ta-lmes-job-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda121-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda124-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda128-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-cuda128-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm62-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-vllm-orchestrator-gateway-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/rhai-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-olm-catalogd-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "python-idna",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Update Service",
        "fix_state": "Not affected",
        "package_name": "openshift-update-service/openshift-update-service-rhel8",
        "cpe": "cpe:/a:redhat:openshift_update_service:5"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Fix deferred",
        "package_name": "container-native-virtualization/ocp-virt-validation-checkup-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "python-idna",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/foreman-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-host-inventory-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-insights-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-puptoo-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vmaas-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vulnerability-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-yuptoo-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Fix deferred",
        "package_name": "rhtas/model-transparency-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Fix deferred",
        "package_name": "rhtas/segment-reporting-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/tuffer-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/tuftool-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Not affected",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      },
      {
        "product_name": "Red Hat Update Infrastructure 4 for Cloud Providers",
        "fix_state": "Fix deferred",
        "package_name": "python-idna",
        "cpe": "cpe:/a:redhat:rhui:4::el8"
      },
      {
        "product_name": "Self-service automation portal 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/bootc-automation-portal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_portal:2"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Fix deferred",
        "package_name": "stf/service-telemetry-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Fix deferred",
        "package_name": "stf/smart-gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-45409\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-45409\nhttps://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"
    ],
    "name": "CVE-2026-45409",
    "mitigation": {
      "value": "To mitigate this denial-of-service vulnerability, applications utilizing the `idna` Python library should implement input validation to ensure that domain names do not exceed the standard 253-character length limit before being passed to the `idna.encode()` function. This operational control prevents the processing of excessively long inputs that could lead to resource exhaustion and service unavailability.\nApplications that pass user-controlled data directly to `idna.encode()` without validation checks (e.g.: DNS length < 254 chars) are affected.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-09T00:00:00Z",
    "bugzilla": {
      "description": "openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()",
      "id": "2481898",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "A flaw was found in OpenSSL. When processing a specially crafted PKCS#7 or S/MIME (Secure/Multipurpose Internet Mail Extensions) signed message, a heap use-after-free vulnerability in the PKCS7_verify() function can be triggered. This occurs if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, leading to incorrect memory deallocation. A remote attacker could exploit this to cause application crashes, memory corruption, or potentially achieve remote code execution."
    ],
    "statement": "This High severity heap use-after-free flaw in OpenSSL's PKCS7_verify() function can be triggered by processing a specially crafted PKCS#7 or S/MIME signed message. This could lead to application crashes, memory corruption, or potentially remote code execution, impacting services that handle such messages. The vulnerability specifically affects applications utilizing OpenSSL PKCS#7 APIs, while those using CMS APIs are not impacted.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25237",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "openssl-1:3.5.5-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58563",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "openssl-1:1.0.2k-26.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36215",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "compat-openssl10-1:1.0.2o-4.el8_10.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26275",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "openssl-1:1.1.1k-16.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26275",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "openssl-1:1.1.1k-16.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36217",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "compat-openssl10-1:1.0.2o-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26275",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "openssl-1:1.1.1k-16.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36217",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "compat-openssl10-1:1.0.2o-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26275",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "openssl-1:1.1.1k-16.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25239",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44438",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "compat-openssl11-1:1.1.1k-5.el9_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25239",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:39012",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "compat-openssl11-1:1.1.1k-4.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:39009",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "compat-openssl11-1:1.1.1k-5.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-06T00:00:00Z",
        "advisory": "RHSA-2026:35869",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "compat-openssl11-1:1.1.1k-5.el9_6.3"
      },
      {
        "product_name": "Cost Management Metrics Operator 4",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39981",
        "cpe": "cpe:/a:redhat:cost_management:4::el9",
        "package": "costmanagement/costmanagement-metrics-rhel9-operator:1783539156"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.8",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47735",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.8::el9",
        "package": "multicluster-engine/console-mce-rhel9:1785078604"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47737",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/console-rhel9:1785078581"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34102",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1782890503"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Under investigation",
        "package_name": "multicluster-engine/hive-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Under investigation",
        "package_name": "multicluster-engine/hypershift-rhel9-operator",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "shim-signed",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-openssl-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Not affected",
        "package_name": "jws-optional-native-components-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7",
        "fix_state": "Not affected",
        "package_name": "jws-optional-native-components-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-45447\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-45447"
    ],
    "name": "CVE-2026-45447",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-10T21:29:28Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Data exposure due to image processing vulnerability",
      "id": "2487739",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487739"
    },
    "cvss3": {
      "cvss3_base_score": "4.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when performing a polynomial distortion an out of bounds over-read of 24 bytes can occur when specifying specific arguments. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.",
      "A flaw was found in ImageMagick. When processing images with specific arguments for polynomial distortion, an out-of-bounds over-read of 24 bytes can occur. This vulnerability could lead to information disclosure or a denial of service (DoS) condition."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-45624\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-45624\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pfvh-m9xv-8966"
    ],
    "name": "CVE-2026-45624",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-10T21:30:51Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service due to excessive resource use in MNG coder",
      "id": "2487732",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487732"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.",
      "A flaw was found in ImageMagick. A remote attacker could exploit a missing check in the Multiple-image Network Graphics (MNG) coder to read more images than allowed by policy. This could lead to excessive resource consumption, resulting in a denial of service (DoS)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32961",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "ImageMagick-0:6.9.10.68-17.el7_9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-45664\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-45664\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g5mf-wqq5-vwg6"
    ],
    "name": "CVE-2026-45664",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-27T00:00:00Z",
    "bugzilla": {
      "description": "kernel: misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()",
      "id": "2481955",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481955"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-1285",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nmisc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()\nibmasm_handle_mouse_interrupt() performs an out-of-bounds MMIO read\nwhen the queue reader or writer index from hardware exceeds\nREMOTE_QUEUE_SIZE (60).\nA compromised service processor can trigger this by writing an\nout-of-range value to the reader or writer MMIO register before\nasserting an interrupt. Since writer is re-read from hardware on\nevery loop iteration, it can also be set to an out-of-range value\nafter the loop has already started.\nThe root cause is that get_queue_reader() and get_queue_writer() return\nraw readl() values that are passed directly into get_queue_entry(),\nwhich computes:\nqueue_begin + reader * sizeof(struct remote_input)\nwith no bounds check. This unchecked MMIO address is then passed to\nmemcpy_fromio(), reading 8 bytes from unintended device registers.\nFor sufficiently large values the address falls outside the PCI BAR\nmapping entirely, triggering a machine check exception.\nFix by checking both indices against REMOTE_QUEUE_SIZE at the top of\nthe loop body, before any call to get_queue_entry(). On an out-of-range\nvalue, reset the reader register to 0 via set_queue_reader() before\nbreaking, so that normal queue operation can resume if the corrupted\nhardware state is transient.",
      "A flaw was found in the Linux kernel's `ibmasm` module. A compromised service processor can exploit this by manipulating specific hardware registers, causing the system to read data from an unintended memory location. This out-of-bounds read can lead to a system crash, resulting in a Denial of Service (DoS)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46022\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46022\nhttps://lore.kernel.org/linux-cve-announce/2026052747-CVE-2026-46022-f6dc@gregkh/T"
    ],
    "name": "CVE-2026-46022",
    "csaw": false
  },
  {
    "public_date": "2026-05-27T00:00:00Z",
    "bugzilla": {
      "description": "kernel: net: caif: clear client service pointer on teardown",
      "id": "2482056",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482056"
    },
    "cwe": "CWE-1341",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nnet: caif: clear client service pointer on teardown\n`caif_connect()` can tear down an existing client after remote shutdown by\ncalling `caif_disconnect_client()` followed by `caif_free_client()`.\n`caif_free_client()` releases the service layer referenced by\n`adap_layer->dn`, but leaves that pointer stale.\nWhen the socket is later destroyed, `caif_sock_destructor()` calls\n`caif_free_client()` again and dereferences the freed service pointer.\nClear the client/service links before releasing the service object so\nrepeated teardown becomes harmless.",
      "A flaw was found in the Linux kernel's CAIF network module. When a client is torn down, the `caif_free_client()` function frees a service pointer but leaves it in a stale state. If the socket is later destroyed, `caif_free_client()` may be called again, attempting to use the previously freed pointer. This can lead to memory corruption and potentially cause a system crash, resulting in a Denial of Service (DoS)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46098\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46098\nhttps://lore.kernel.org/linux-cve-announce/2026052704-CVE-2026-46098-ec82@gregkh/T"
    ],
    "name": "CVE-2026-46098",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-03T00:00:00Z",
    "bugzilla": {
      "description": "kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP",
      "id": "2484456",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484456"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-1287",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\ninet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP\nYizhou Zhao reported that simply having one RAW socket on protocol\nIPPROTO_RAW (255) was dangerous.\nsocket(AF_INET, SOCK_RAW, 255);\nA malicious incoming ICMP packet can set the protocol field to 255\nand match this socket, leading to FNHE cache changes.\ninner = IP(src=\"192.168.2.1\", dst=\"8.8.8.8\", proto=255)/Raw(\"TEST\")\npkt = IP(src=\"192.168.1.1\", dst=\"192.168.2.1\")/ICMP(type=3, code=4, nexthopmtu=576)/inner\n\"man 7 raw\" states:\nA protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able\nto send any IP protocol that is specified in the passed header.\nReceiving of all IP protocols via IPPROTO_RAW is not possible\nusing raw sockets.\nMake sure we drop these malicious packets.",
      "A flaw was found in the Linux kernel's handling of RAW sockets using IPPROTO_RAW. A remote attacker could send a specially crafted ICMP (Internet Control Message Protocol) packet. This malicious packet could set the protocol field to 255, causing it to be processed by a RAW socket configured for IPPROTO_RAW. This leads to unintended FNHE (Flow N-tuple Hash Entry) cache changes, which could result in unexpected network behavior."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46266\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46266\nhttps://lore.kernel.org/linux-cve-announce/2026060337-CVE-2026-46266-1e5e@gregkh/T"
    ],
    "name": "CVE-2026-46266",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-15T14:57:31Z",
    "bugzilla": {
      "description": "vim: command injection when decompressing .tgz archives",
      "id": "2477915",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477915"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-78",
    "details": [
      "Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in\nruntime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag, allowing a crafted archive filename to trigger Vim cmdline-special expansion and execute shell commands in the user's context. This vulnerability is fixed in 9.2.0479.",
      "A flaw was found in Vim. When decompressing .tgz archives, the Vimuntar function builds shell commands using shellescape() without the {special} flag. This allows a specially crafted archive filename to trigger Vim cmdline-special expansion and execute arbitrary commands in the context of the current user."
    ],
    "statement": "To exploit this issue, an attacker needs to convince a user to decompress a .tgz archive with a specially crafted filename. Additionally, possible arbitrary command execution is restricted to the context of the user running Vim. These conditions limit the exposure of this vulnerability and the potential of a full system compromise. Due to these reasons, this flaw has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38509",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "vim-2:9.1.083-9.el10_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30900",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38510",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-27.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38510",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-27.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33453",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33453",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "vim-2:8.0.1763-15.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34477",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34477",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "vim-2:8.0.1763-19.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34476",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34476",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "vim-2:8.0.1763-20.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38511",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38511",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28133",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "vim-2:8.2.2637-20.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:28049",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "vim-2:8.2.2637-20.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:28050",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "vim-2:8.2.2637-22.el9_6.3"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46483\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46483\nhttps://github.com/vim/vim/commit/3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1\nhttps://github.com/vim/vim/releases/tag/v9.2.0479\nhttps://github.com/vim/vim/security/advisories/GHSA-2fpv-9ff7-xg5w"
    ],
    "name": "CVE-2026-46483",
    "mitigation": {
      "value": "To mitigate this vulnerability, do not decompress untrusted .tgz archives with the Vimuntar command. Use 'tar -x -z -f' directly, instead.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-10T21:31:57Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via out-of-bounds write when processing multiple images",
      "id": "2487729",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487729"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when reading multiple images with different dimensions an out of bounds heap write can occur. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.",
      "A flaw was found in ImageMagick, a free and open-source software for editing and manipulating digital images. When processing multiple images with varying dimensions, an out-of-bounds heap write can occur. This vulnerability could allow a remote attacker to cause a denial of service (DoS) condition, making the affected system or application unavailable."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32961",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "ImageMagick-0:6.9.10.68-17.el7_9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46520\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46520\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-36wm-hprc-mcf5"
    ],
    "name": "CVE-2026-46520",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-10T21:40:44Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via out-of-bounds write in LZMA MIFF encoder",
      "id": "2487766",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487766"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.",
      "A flaw was found in ImageMagick. When processing an image with LZMA compression in the MIFF encoder, a missing check can lead to an out-of-bounds write. This vulnerability could allow an attacker to cause a denial of service (DoS) by providing a specially crafted image file, leading to application instability or crashes."
    ],
    "statement": "This Moderate impact flaw in ImageMagick allows an out-of-bounds write when processing specially crafted image files using LZMA compression within the MIFF encoder. While requiring user interaction to process a malicious image, this vulnerability could lead to a denial of service, causing application instability or crashes in Red Hat products that utilize ImageMagick for image manipulation.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46521\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46521\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jcqp-6r6f-3mfx"
    ],
    "name": "CVE-2026-46521",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-10T21:30:41Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via crafted MIFF file",
      "id": "2487730",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487730"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-835",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CPU exhaustion. Versions 7.1.2.23 and 6.9.13-48 fix the issue.",
      "A flaw was found in ImageMagick. A remote attacker could provide a specially crafted MIFF (Magick Image File Format) file, which, due to a missing check in the MIFF decoder, would lead to an infinite loop. This vulnerability results in CPU exhaustion, causing a Denial of Service (DoS) for the affected system."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32961",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "ImageMagick-0:6.9.10.68-17.el7_9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46522\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46522\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7gg8-qqx7-92g5"
    ],
    "name": "CVE-2026-46522",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-10T21:22:02Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via crafted MSL image leading to heap-use-after-free",
      "id": "2487743",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487743"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a heap-use-after-free. Versions 7.1.2.23 and 6.9.13-48 fix the issue.",
      "A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. A remote attacker could exploit this vulnerability by providing a specially crafted MSL (Magick Scripting Language) image. Processing this malicious image could trigger a heap-use-after-free error, leading to a denial of service (DoS) condition."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32961",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "ImageMagick-0:6.9.10.68-17.el7_9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46523\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46523\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5r4x-w6p5-222q"
    ],
    "name": "CVE-2026-46523",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-10T19:46:23Z",
    "bugzilla": {
      "description": "atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen",
      "id": "2487669",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487669"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-77",
    "details": [
      "Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1.26.3 and 1.28.4 contain a patch for the issue. This is the same defect class as CVE-2023-51698 (CBT `--checkpoint-action` injection in `comics-document.c`, fixed in 1.6.2) but in a different code path (`shell/ev-application.c`) that the original patch did not touch.",
      "A flaw was found in Atril, Evince and Xreader. A malicious link inside a specially crafted PDF document can cause arbitrary code execution when clicked due to improper quoting of attacker-controlled PDF link-destination fields during remote go-to (/GoToR) actions. This issue allows an attacker to execute arbitrary code with the privileges of the user that clicked on the embedded link."
    ],
    "statement": "To exploit this issue, an attacker needs to convince a user to open a specially crafted PDF document and to click on a malicious link inside the document, limiting its exposure. Also, this flaw allows an attacker to execute arbitrary code with the privileges of the user that clicked on the embedded link, which is usually a low-privileged user account, limiting its impact. However, an attacker can package a single file that is simultaneously a valid PDF document and a valid ELF shared library, making the exploit self-contained and exploitable via a single click. Due to these reasons, this vulnerability has been rated with an important severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41904",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "evince-0:3.28.2-11.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:28998",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "evince-0:3.28.4-17.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43398",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "evince-0:3.28.4-11.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43398",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "evince-0:3.28.4-11.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46467",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "evince-0:3.28.4-16.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46467",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "evince-0:3.28.4-16.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42692",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "evince-0:3.28.4-16.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42692",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "evince-0:3.28.4-16.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27819",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "evince-0:40.5-4.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39115",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "evince-0:40.5-2.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33416",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "evince-0:40.5-2.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33169",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "evince-0:40.5-2.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "evince",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46529\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46529\nhttp://www.openwall.com/lists/oss-security/2026/05/19/34\nhttp://www.openwall.com/lists/oss-security/2026/05/21/7\nhttp://www.openwall.com/lists/oss-security/2026/05/22/11\nhttps://github.com/mate-desktop/atril/releases/tag/v1.26.3\nhttps://github.com/mate-desktop/atril/releases/tag/v1.28.4\nhttps://github.com/mate-desktop/atril/security/advisories/GHSA-vgv2-m826-8f6f\nhttps://lists.debian.org/debian-lts-announce/2026/05/msg00041.html\nhttps://lists.debian.org/debian-lts-announce/2026/05/msg00042.html"
    ],
    "name": "CVE-2026-46529",
    "mitigation": {
      "value": "To mitigate this vulnerability, do not click on links inside PDF documents from untrusted or unverified sources.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-10T21:44:40Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via crafted argument in fx operation",
      "id": "2487747",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487747"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-120",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23, due to a missing depth check a stack overflow can occur in the fx operation by passing a crafted argument. This issue has been patched in version 7.1.2-23.",
      "A flaw was found in ImageMagick. A local attacker could exploit a missing depth check in the fx operation by providing a specially crafted argument. This could lead to a stack overflow, resulting in a denial of service (DoS) for the application."
    ],
    "statement": "This Low impact flaw in ImageMagick allows a local attacker to trigger a denial of service by providing a specially crafted argument to the `fx` operation. Exploitation requires local access and user interaction, limiting the attack vector to scenarios where untrusted local users can execute ImageMagick with arbitrary inputs.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46557\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46557\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rcr6-g7jc-f57g"
    ],
    "name": "CVE-2026-46557",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-10T21:45:44Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of service via heap buffer overwrite in JP2 processing",
      "id": "2487755",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487755"
    },
    "cvss3": {
      "cvss3_base_score": "6.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an incorrect check in the JP2 will result in an heap buffer over-write of a single byte when specifying certain options. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.",
      "A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. An incorrect check during JPEG 2000 (JP2) image processing, when certain options are specified, can lead to a heap buffer overwrite of a single byte. This vulnerability could allow a local attacker to cause a denial of service (DoS) by crashing the application."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46559\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46559\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-533m-3wf6-c33v"
    ],
    "name": "CVE-2026-46559",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Synopsis"
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46569\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46569"
    ],
    "name": "CVE-2026-46569",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Synopsis"
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46570\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46570"
    ],
    "name": "CVE-2026-46570",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Synopsis"
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46571\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46571"
    ],
    "name": "CVE-2026-46571",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Synopsis"
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46572\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46572"
    ],
    "name": "CVE-2026-46572",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-07-22T13:07:40Z",
    "bugzilla": {
      "description": "unbound: Unbound: Information disclosure via DNSSEC wildcard replay",
      "id": "2506139",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506139"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-358",
    "details": [
      "In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. When the resolving thread puts secure on the rrset, and another thread that is on the serve expired path then picks up the updated rrset contents with the secure status for a reply, it can be used to change a specific record, next to a wildcard that could be covered by the wildcard, into the wildcard. A malicious actor can exploit the possible poisonous effect by having any DNSSEC-singed domain (irrelevant to the victim domain) and a CNAME wrapper record that points to a record next to a wildcard (that could be covered by the wildcard). Then quering Unbound for the wildcard sibling record would seed the secure message. A later (after expiry) query for the CNAME wrapper would need to resolve the target sibling record. If the wildcard replay is injected into the response, the wildcard rrset will update the expired sibling record with a secure status before completing proper wildcard validation with NSEC records and eventually treating the CNAME wrapper answer as bogus. The updated poisoned rrset is now secure and points to the wildcard. This vulnerability is explicit for the serve expired path and needs injection of the signed wildcard rrset without the NSEC accompanying rrset.",
      "A flaw was found in Unbound, a Domain Name System (DNS) resolver. A remote attacker can exploit a vulnerability in how Unbound handles expired DNSSEC (DNS Security Extensions) records. By injecting a replayed wildcard record set, an attacker can cause Unbound to temporarily consider it secure, leading to the caching of a poisoned record. This can result in information disclosure, where a legitimate DNS record is incorrectly resolved as a wildcard record, potentially misdirecting network traffic."
    ],
    "statement": "This issue has a Low impact as it requires a sophisticated attacker to inject specific DNSSEC wildcard replay data. The vulnerability in Unbound's handling of expired DNSSEC records could lead to temporary information disclosure, where a legitimate DNS record is briefly misresolved as a wildcard. This limited impact and the high attack complexity contribute to its Low severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43588",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "unbound-main-1.25.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46582\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46582\nhttps://www.nlnetlabs.nl/downloads/unbound/CVE-2026-46582.txt"
    ],
    "name": "CVE-2026-46582",
    "mitigation": {
      "value": "To mitigate this issue, disable the serve-expired feature by setting serve-expired: no in the Unbound configuration if it is not strictly required. This entirely removes the vulnerable code path where the cache poisoning occurs.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-10T21:46:45Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Heap buffer over-write via `magick -distribute-cache` service connection",
      "id": "2487749",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487749"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-write in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.",
      "A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. A remote attacker, by connecting to a `magick -distribute-cache` service, can trigger a heap buffer over-write in the server process. This vulnerability can lead to a denial of service (DoS) due to memory corruption, potentially making the service unavailable."
    ],
    "statement": "Moderate: A heap buffer overwrite vulnerability in ImageMagick's `magick -distribute-cache` service allows a remote, unauthenticated attacker to cause a denial of service. This flaw requires the `magick -distribute-cache` service to be explicitly enabled and exposed, as it is not enabled by default in Red Hat products, limiting its impact to specific configurations.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32961",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "ImageMagick-0:6.9.10.68-17.el7_9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46692\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46692\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p93h-f2jc-477j"
    ],
    "name": "CVE-2026-46692",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-10T21:47:41Z",
    "bugzilla": {
      "description": "ImageMagick: Magick.NET: ImageMagick: Information disclosure via file descriptor hijacking due to a race condition.",
      "id": "2487754",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487754"
    },
    "cvss3": {
      "cvss3_base_score": "4.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-910",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can hijack a file descriptor in the server process when a race condition is met. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.",
      "A flaw was found in ImageMagick. An attacker able to connect to a `magick -distribute-cache` service could exploit a race condition to hijack a file descriptor in the server process. This could lead to unauthorized access to sensitive information."
    ],
    "statement": "This flaw is rated as Low impact. It requires an attacker to have high privileges and the ability to connect to a `magick -distribute-cache` service. Exploitation is further limited by the high attack complexity and a race condition, making it difficult to reliably hijack a file descriptor for information disclosure. This service is not typically enabled or exposed by default in Red Hat products.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-46693\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-46693\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4g75-9r48-jf92"
    ],
    "name": "CVE-2026-46693",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-11T18:32:14Z",
    "bugzilla": {
      "description": "vim: Vim: Arbitrary Code Execution via crafted directory names",
      "id": "2487964",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487964"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-140",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name to break out of the string context and execute arbitrary Vimscript, including shell commands via system() and :!, the next time the history file is sourced. This issue has been patched in version 9.2.0495.",
      "A flaw was found in Vim, an open-source text editor. This vulnerability, located in the netrw plugin, involves a code injection issue when the editor processes directory paths. A malicious directory name, if crafted by an attacker, could bypass security measures and allow for the execution of unauthorized commands. This could lead to arbitrary code execution on the affected system."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38509",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "vim-2:9.1.083-9.el10_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55431",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38510",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-27.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38510",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-27.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38511",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38511",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.10"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54769",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202608130832-0"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-47162\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-47162\nhttps://github.com/vim/vim/commit/f08ab2f4d7d2947c8dd6c179ae08ee6146a2694b\nhttps://github.com/vim/vim/releases/tag/v9.2.0495\nhttps://github.com/vim/vim/security/advisories/GHSA-crm5-rh6j-2c7c"
    ],
    "name": "CVE-2026-47162",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-10T21:50:30Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Information disclosure due to missing authentication in distributed pixel cache",
      "id": "2487760",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487760"
    },
    "cvss3": {
      "cvss3_base_score": "4.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-306",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, the distributed pixel cache was originally designed to operate without a challenge–response authentication model. This has been changed in versions 6.9.13-48 and 7.1.2-23.",
      "A flaw was found in ImageMagick, a software used for editing and manipulating digital images. The distributed pixel cache, a component responsible for managing image data, lacked a necessary authentication mechanism. This oversight could allow a local attacker with high privileges to access sensitive data, resulting in information disclosure."
    ],
    "statement": "This flaw in ImageMagick has a Low impact, as it requires a local attacker with high privileges to exploit the missing authentication in the distributed pixel cache. This could lead to information disclosure, but the stringent access requirements significantly reduce the risk in most Red Hat environments.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-47165\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-47165\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2rgj-gx5x-f62w"
    ],
    "name": "CVE-2026-47165",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-10T21:51:18Z",
    "bugzilla": {
      "description": "ImageMagick: Magick.NET: ImageMagick: Information Disclosure and Denial of Service via heap buffer over-read",
      "id": "2487748",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487748"
    },
    "cvss3": {
      "cvss3_base_score": "6.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.",
      "A flaw was found in ImageMagick, a widely used software for image editing. An attacker with high privileges and local access could exploit a vulnerability in the `magick -distribute-cache` service. By causing a heap buffer over-read, this could lead to the disclosure of sensitive information and potentially disrupt the availability of the service."
    ],
    "statement": "Moderate: This flaw in ImageMagick could lead to information disclosure and denial of service. Exploitation requires an attacker to have high privileges and local access to the system, specifically targeting the `magick -distribute-cache` service. This limits the overall risk in typical Red Hat Enterprise Linux deployments.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-47166\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-47166\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6gxq-f64p-5w6f"
    ],
    "name": "CVE-2026-47166",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-11T18:31:44Z",
    "bugzilla": {
      "description": "vim: Vim: Arbitrary code execution via crafted step-definition patterns",
      "id": "2487996",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487996"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-94",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) on Vim builds with +ruby support. Step-definition patterns read from .rb files under the repository's features/*/ or stories/*/ directories are embedded into a Ruby Kernel.eval argument without sufficient escaping, allowing a crafted pattern in an attacker-controlled repository to execute arbitrary Ruby (and through it arbitrary shell commands) when the user invokes a step-jump mapping ([d, ]d). This issue has been patched in version 9.2.0496.",
      "A flaw was found in Vim, a command-line text editor. This vulnerability, identified as a code injection, affects the cucumber filetype plugin when Vim is configured with Ruby support. An attacker could exploit this by creating a malicious repository containing specially crafted step-definition patterns. If a user opens this repository and triggers a specific function, the crafted patterns are unsafely processed, potentially allowing the attacker to execute unauthorized commands on the user's system."
    ],
    "statement": "This Important vulnerability in Vim's cucumber filetype plugin, when configured with Ruby support, allows for arbitrary code execution. An attacker could exploit this by convincing a user to open a specially crafted repository and trigger a specific step-jump mapping, leading to local command execution. This risk is contingent on user interaction with untrusted content and the presence of the Ruby-enabled cucumber plugin.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38509",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "vim-2:9.1.083-9.el10_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55431",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38510",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-27.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38510",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-27.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38511",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38511",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.10"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54769",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202608130832-0"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-47167\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-47167\nhttps://github.com/vim/vim/commit/a65a52d684bc58535ad28a4ae824d22e76399934\nhttps://github.com/vim/vim/releases/tag/v9.2.0496\nhttps://github.com/vim/vim/security/advisories/GHSA-4473-94jm-w5x9"
    ],
    "name": "CVE-2026-47167",
    "mitigation": {
      "value": "To mitigate this issue, users should exercise caution when opening untrusted files or repositories with Vim, particularly those that might trigger the `cucumber` filetype plugin. Avoiding interaction with untrusted content can prevent the execution of malicious step-definition patterns.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-01T17:48:43Z",
    "bugzilla": {
      "description": "github.com/containerd/containerd: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsing",
      "id": "2496126",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496126"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.",
      "A flaw was found in containerd, an open-source container runtime. A remote attacker could exploit this vulnerability by providing a maliciously crafted image. When a container is created from this image, it leads to uncontrolled resource consumption and memory exhaustion, causing the containerd process to terminate. This results in a Denial of Service (DoS) condition, making the container runtime API unavailable and disrupting clients like Docker Engine or Kubernetes."
    ],
    "statement": "Red Hat's container platform uses CRI-O as its container runtime interface, not containerd. While containerd libraries are bundled in some images for OCI image operations (e.g., estargz support via skopeo), the containerd daemon and its CRI plugin (where the vulnerable group-parsing code path exists) are not executed. Therefore, this vulnerability is not exploitable in Red Hat products.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-12T00:00:00Z",
        "advisory": "RHSA-2026:25535",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "kubernetes1-35-main-1.35.6-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-18T00:00:00Z",
        "advisory": "RHSA-2026:26990",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "kubernetes1-36-main-1.36.2-2.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29770",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "opentelemetry-collector-contrib-main-0.155.0-0.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32963",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "grype-main-0.115.0-0.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32974",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "syft-main-1.46.0-0.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:35111",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "trivy-main-0.72.0-0.1.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Not affected",
        "package_name": "assisted/agent-preinstall-image-builder-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Not affected",
        "package_name": "rhai/assisted-installer-agent-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-monitor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Not affected",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Deployment Validation Operator",
        "fix_state": "Not affected",
        "package_name": "dvo/deployment-validation-rhel8-operator",
        "cpe": "cpe:/a:redhat:deployment_validator_operator"
      },
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Not affected",
        "package_name": "exploit-intelligence-tech-preview/agent-client-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Gatekeeper 3",
        "fix_state": "Not affected",
        "package_name": "gatekeeper/gatekeeper-rhel9",
        "cpe": "cpe:/a:redhat:gatekeeper:3"
      },
      {
        "product_name": "Kernel Module Management Operator for Red Hat Openshift",
        "fix_state": "Not affected",
        "package_name": "kmm/kernel-module-management-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:kernel_module_management:2"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/logging-loki-rhel9",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Not affected",
        "package_name": "lvms4/lvms-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/machine-deletion-remediation-operator-bundle",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/machine-deletion-remediation-rhel9-operator",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "MCP Server for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-mcp-beta/openshift-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_mcp_server:0"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Not affected",
        "package_name": "rhmtc/openshift-migration-log-reader-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Not affected",
        "package_name": "rhmtc/openshift-migration-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-validation-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-api-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-cli-download-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-openstack-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-operator-bundle",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-ova-provider-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-populator-controller-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-rhv-populator-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-validation-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-virt-v2v-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-vsphere-xcopy-volume-populator-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-installer-agent-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-installer-agent-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-installer-controller-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-installer-controller-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-installer-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-service-8-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/assisted-service-9-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/must-gather-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Not affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-agent-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Not affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Not affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-manager-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Multicluster Global Hub",
        "fix_state": "Not affected",
        "package_name": "multicluster-globalhub/multicluster-globalhub-rhel9-operator",
        "cpe": "cpe:/a:redhat:multicluster_globalhub"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Not affected",
        "package_name": "workload-availability/node-healthcheck-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "OpenShift API for Data Protection",
        "fix_state": "Not affected",
        "package_name": "oadp/oadp-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "helm",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Not affected",
        "package_name": "ocp-tools-4/jenkins-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/lightspeed-agentic-sandbox-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/openshift-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-entrypoint-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-results-watcher-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Not affected",
        "package_name": "openshift-pipelines/pipelines-sidecarlogresults-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Not affected",
        "package_name": "openshift-serverless-1/serverless-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Not affected",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:0"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Not affected",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:1"
      },
      {
        "product_name": "Power monitoring for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-power-monitoring/power-monitoring-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_power_monitoring"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-grafana-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/multicloud-integrations-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/multiclusterhub-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/multicluster-operators-channel-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/multicluster-operators-subscription-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/submariner-operator-bundle",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/submariner-rhel9-operator",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-main-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-main-rhel9",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-operator-bundle",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-rhel8-operator",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-rhel9-operator",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-roxctl-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-roxctl-rhel9",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-scanner-v4-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Not affected",
        "package_name": "advanced-cluster-security/rhacs-scanner-v4-rhel9",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/aap-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/aap-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/aap-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/aap-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Build of Kueue",
        "fix_state": "Not affected",
        "package_name": "kueue/kueue-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:kueue_operator:1"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Not affected",
        "package_name": "rhceph/rhceph-promtail-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 9",
        "fix_state": "Not affected",
        "package_name": "rhceph/alloy-rhel10",
        "cpe": "cpe:/a:redhat:ceph_storage:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "container-tools:rhel8/buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "container-tools:rhel8/conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "container-tools:rhel8/podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "container-tools:rhel8/skopeo",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "buildah",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "podman",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-spark-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/rhai-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "conmon",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "cri-o",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "microshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/cnf-tests-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/cnf-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/container-networking-plugins-microshift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4-dev-preview-beta/openperouter-edge-rhel10-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4-dev-preview-beta/openperouter-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4-dev-preview-beta/openperouter-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/kube-compare-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/lifecycle-agent-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/metallb-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/metallb-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/microshift-bootc-rhel10",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/microshift-bootc-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/network-tools-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/network-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/numaresources-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/numaresources-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/numaresources-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/oc-mirror-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/oc-mirror-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-csr-approver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-csr-approver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-node-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-orchestrator-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-orchestrator-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ansible-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-aws-ebs-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-aws-efs-csi-driver-container-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-cluster-api-controllers-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-disk-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-file-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli-artifacts",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-ingress-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-olm-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-console",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-console-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-container-networking-plugins-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-container-networking-plugins-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-driver-manila-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-driver-nfs-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-driver-shared-resource-mustgather-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-driver-shared-resource-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-external-provisioner-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-deployer",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-deployer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-builder",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-builder-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-registry",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-helm-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-helm-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-hyperkube-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-kube-proxy-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-local-storage-mustgather-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-local-storage-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-api-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-os-images-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-must-gather",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-node-feature-discovery",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-node-feature-discovery-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-catalogd-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-catalogd-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-operator-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-operator-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-rukpak-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-rukpak-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openstack-cinder-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-openstack-cloud-controller-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-framework-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-lifecycle-manager",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-lifecycle-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-registry",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-sdk-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-sdk-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ovn-kubernetes",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ovn-kubernetes-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-powervs-block-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-sdn-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-secrets-store-csi-mustgather-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-secrets-store-csi-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-smb-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tools-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-csi-driver-syncer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ptp-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ptp-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ztp-site-generate-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift-clients",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift-kni/commatrix",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "podman",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/mcg-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/odf-cloudnative-pg-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4",
        "fix_state": "Not affected",
        "package_name": "odf4/odf-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/traefik-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Not affected",
        "package_name": "openshift4-wincw/windows-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/argocd-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/argocd-rhel9",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Not affected",
        "package_name": "openshift-gitops-1/must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/cnv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/cnv-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/multus-dynamic-networks-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/osp-director-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel9/osp-director-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/openstack-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/rabbitmq-cluster-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/ec-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/policy-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Not affected",
        "package_name": "rhtpa/rhtpa-rhel9-operator",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-47262\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-47262\nhttps://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq"
    ],
    "name": "CVE-2026-47262",
    "mitigation": {
      "value": "No mitigation is needed for Red Hat products. The vulnerable code path in containerd's CRI plugin group-parsing logic is not executed because Red Hat uses CRI-O as the container runtime. Products that bundle containerd as a library dependency for OCI image operations are not affected.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-23T00:00:00Z",
    "bugzilla": {
      "description": "squid: memory disclosure in FTP gateway",
      "id": "2492882",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492882"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.",
      "A flaw was found in Squid. Due to improper input validation, an out-of-bounds read can occur in the FTP gateway. This issue allows an authenticated and trusted client to read memory from random transactions when accessing a misbehaving FTP server using the Squid gateway feature."
    ],
    "statement": "To exploit this issue, an attacker must have a valid account on the Squid proxy and must also control an FTP server reachable from the proxy on port 21. HTTPS traffic handled via CONNECT tunnels (the vast majority of modern web traffic) is opaque to the proxy because the underlying request data is encrypted and Squid does not have access to it. The impact is limited to information disclosure of cleartext HTTP request contents or traffic in TLS-terminating (SSL bump) proxy configurations where Squid decrypts and inspects traffic. FTP protocol usage has declined considerably in most environments since major browsers removed FTP support, further narrowing the practical attack surface. Due to these reasons, this vulnerability has been rated with a moderate severity.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "squid34",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "squid:4/squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-47729\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-47729\nhttps://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg"
    ],
    "name": "CVE-2026-47729",
    "mitigation": {
      "value": "When FTP access is not required, block FTP traffic at the proxy by adding the following settings to the squid.conf configuration file above any custom 'http_access allow' rules:\n~~~\nacl FTP proto FTP\nhttp_access deny FTP\n~~~\nWhen FTP access is required, configure Squid to only allow FTP access to specific and trusted destination domains. See the example below for restricting FTP access to the 'trusted.server.example.com' domain:\n~~~\nacl FTP proto FTP\nacl ftp_allowlist dstdomain .trusted.server.example.com\nhttp_access deny FTP !ftp_allowlist\n~~~",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-24T14:33:35Z",
    "bugzilla": {
      "description": "libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing",
      "id": "2450768",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450768"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.",
      "A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution."
    ],
    "statement": "A flaw in the libtiff library, affecting the processing of specially crafted TIFF files, could lead to a denial of service or potentially arbitrary code execution. This vulnerability, caused by a signed integer overflow during TIFF image processing, results in an out-of-bounds heap write. Red Hat products that process untrusted TIFF files using libtiff may be impacted.",
    "acknowledgement": "Red Hat would like to thank PrymEvol and Quang Luong for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12265",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "libtiff-0:4.6.0-6.el10_1.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19150",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libtiff-0:4.6.0-8.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19586",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libtiff-0:4.6.0-6.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:24992",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "compat-libtiff3-0:3.9.4-12.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25910",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libtiff-0:4.0.3-35.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16055",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libtiff-0:4.0.9-37.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20585",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "compat-libtiff3-0:3.9.4-15.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14929",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "mingw-libtiff-0:4.0.9-4.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19659",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libtiff-0:4.0.9-18.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20583",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "compat-libtiff3-0:3.9.4-13.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19659",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libtiff-0:4.0.9-18.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20583",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "compat-libtiff3-0:3.9.4-13.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19657",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libtiff-0:4.0.9-21.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20591",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "compat-libtiff3-0:3.9.4-13.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19657",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "libtiff-0:4.0.9-21.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20591",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "compat-libtiff3-0:3.9.4-13.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19657",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "libtiff-0:4.0.9-21.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20591",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "compat-libtiff3-0:3.9.4-13.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19604",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libtiff-0:4.0.9-29.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20592",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "compat-libtiff3-0:3.9.4-13.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19604",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libtiff-0:4.0.9-29.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20592",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "compat-libtiff3-0:3.9.4-13.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12271",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libtiff-0:4.4.0-15.el9_7.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19363",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libtiff-0:4.4.0-18.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19608",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "libtiff-0:4.2.0-3.el9_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19609",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libtiff-0:4.4.0-8.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19702",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "libtiff-0:4.4.0-12.el9_4.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19585",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libtiff-0:4.4.0-13.el9_6.4"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30078",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1782352950"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30087",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1782352919"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30088",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782353093"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30089",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1782352847"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-26T00:00:00Z",
        "advisory": "RHSA-2026:30349",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libtiff-main-4.7.1-2.2.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33388",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libtiff-main-4.7.1-2.3.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "libtiff",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4775\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4775"
    ],
    "name": "CVE-2026-4775",
    "mitigation": {
      "value": "To mitigate this issue, avoid processing untrusted or maliciously crafted TIFF files with applications linked against the libtiff library. If processing untrusted TIFF files is unavoidable, consider running the affected applications within a sandboxed environment to limit the potential impact of successful exploitation. This operational control helps contain the effects of an out-of-bounds write, reducing the risk of denial of service or arbitrary code execution.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-25T17:22:21Z",
    "bugzilla": {
      "description": "jq: jq: Denial of Service via deeply nested array comparison",
      "id": "2493034",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493034"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq's recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2.",
      "A flaw was found in jq, a command-line JSON processor. This vulnerability allows a local user or an attacker providing malicious input to cause a denial of service (DoS) by comparing two sufficiently deeply nested arrays using the '==' operator. This action exhausts the C stack due to uncontrolled recursion, leading to a crash of the jq process."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29986",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-47770\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-47770\nhttps://github.com/jqlang/jq/security/advisories/GHSA-3pgx-frr7-3jxp"
    ],
    "name": "CVE-2026-47770",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-20T05:43:46Z",
    "bugzilla": {
      "description": "memcached: memcached: Username enumeration via timing side channel",
      "id": "2480089",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480089"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-208",
    "details": [
      "In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.",
      "A flaw was found in memcached. A remote attacker can exploit a timing side channel during Simple Authentication and Security Layer (SASL) password database authentication. This vulnerability allows an attacker to observe subtle timing differences, which could be used to enumerate valid usernames."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27842",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "memcached-0:1.6.23-7.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27862",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "memcached-0:1.6.9-7.el9_8.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "memcached",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "memcached",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "memcached",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-47783\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-47783\nhttps://github.com/memcached/memcached/commit/d13f282b4bce33a9c33b8a1bbf07f12114160fed\nhttps://github.com/memcached/memcached/compare/1.6.41...1.6.42\nhttps://github.com/memcached/memcached/wiki/ReleaseNotes1642"
    ],
    "name": "CVE-2026-47783",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-20T05:45:37Z",
    "bugzilla": {
      "description": "memcached: Memcached: Information disclosure via timing side channel",
      "id": "2480088",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480088"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-208",
    "details": [
      "In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.",
      "A flaw was found in memcached. This vulnerability involves a timing side channel during SASL (Simple Authentication and Security Layer) password database authentication. A remote attacker could potentially exploit the timing differences in the password verification process to infer sensitive password data. This could lead to unauthorized access to the memcached instance."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23261",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "memcached-main-1.6.42-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "memcached",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "memcached",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "memcached",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "memcached",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "memcached",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-47784\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-47784\nhttps://github.com/memcached/memcached/commit/d13f282b4bce33a9c33b8a1bbf07f12114160fed\nhttps://github.com/memcached/memcached/compare/1.6.41...1.6.42\nhttps://github.com/memcached/memcached/wiki/ReleaseNotes1642"
    ],
    "name": "CVE-2026-47784",
    "mitigation": {
      "value": "To mitigate this issue, restrict network access to the memcached service to only trusted clients and networks using firewall rules. If SASL authentication is not strictly required, consider disabling it. If SASL is necessary, ensure that strong, unique passwords are used and rotated regularly.\nExample firewall rule (adjust port and source as needed):\n`firewall-cmd --permanent --add-rich-rule='rule family=\"ipv4\" source address=\"<TRUSTED_IP_RANGE>\" port port=\"11211\" protocol=\"tcp\" accept'`\n`firewall-cmd --reload`\nTo bind memcached to localhost, edit `/etc/sysconfig/memcached` and set `OPTIONS=\"-l 127.0.0.1\"`. Restart the memcached service:\n`systemctl restart memcached`\nNote that restarting the memcached service will clear all cached data.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-17T14:04:32Z",
    "bugzilla": {
      "description": "nginx: NGINX: Memory disclosure or denial of service via ngx_http_charset_module heap buffer over-read",
      "id": "2489858",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2489858"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. \nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in NGINX. Remote, unauthenticated attackers can exploit a vulnerability in the `ngx_http_charset_module` when specific charset configurations are present. This can lead to a heap buffer over-read, potentially causing limited disclosure of memory or a denial of service by restarting the NGINX worker process."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-19T00:00:00Z",
        "advisory": "RHSA-2026:27197",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nginx-main-1.30.3-2.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nginx:1.24/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nginx:1.26/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-48142\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-48142\nhttps://my.f5.com/manage/s/article/K000161585"
    ],
    "name": "CVE-2026-48142",
    "mitigation": {
      "value": "To mitigate this issue, avoid configuring NGINX with both `source_charset utf-8;` and an additional `charset` directive within the same location block in the `ngx_http_charset_module`. If these directives are not essential for your NGINX deployment, removing one or both will prevent the vulnerability from being exploited. After modifying the NGINX configuration, reload the NGINX service using `systemctl reload nginx`. This action may temporarily interrupt active connections.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-03T13:16:47Z",
    "bugzilla": {
      "description": "django: Django: Information disclosure via improper handling of Vary header whitespace",
      "id": "2484372",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484372"
    },
    "cvss3": {
      "cvss3_base_score": "3.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-524",
    "details": [
      "An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.\n`django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Navid Rezazadeh for reporting this issue.",
      "A flaw was found in Django. Remote attackers can exploit this vulnerability due to `django.utils.cache.has_vary_header()` not properly stripping whitespace from `Vary` response header values. This allows an attacker to read cached responses by sending requests to URLs with whitespace-padded `Vary` header values, leading to information disclosure."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-48587\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-48587\nhttps://docs.djangoproject.com/en/dev/releases/security/\nhttps://groups.google.com/g/django-announce\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/"
    ],
    "name": "CVE-2026-48587",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-07-07T14:00:00Z",
    "bugzilla": {
      "description": "django: Django: Information disclosure due to improper caching of Set-Cookie responses",
      "id": "2497327",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497327"
    },
    "cvss3": {
      "cvss3_base_score": "3.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-524",
    "details": [
      "An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.\n`UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Chris Whyland for reporting this issue.",
      "A flaw was found in Django. When django.middleware.cache.UpdateCacheMiddleware or django.views.decorators.cache.cache_page is in use, responses that set a cookie are not excluded from caching if the request includes any cookie, even when that cookie is unrelated to the response (for example, a language or theme preference). A remote attacker can retrieve a cached response intended for another user and obtain sensitive cookie data from the stored Set-Cookie header."
    ],
    "statement": "This flaw is rated as Low impact. When Django's UpdateCacheMiddleware or cache_page decorator is configured, responses containing sensitive Set-Cookie headers may be improperly cached and subsequently disclosed to other users if the initial request included any cookie. This issue primarily affects Red Hat products utilizing Django with specific caching configurations, potentially leading to limited information exposure.",
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Self-service automation portal 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/bootc-automation-portal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_portal:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-48588\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-48588"
    ],
    "name": "CVE-2026-48588",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-06T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "status": ""
    },
    "cwe": "",
    "details": [
      "radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, `print_ff()` copies up to 2032 bytes from attacker-controlled packet data into a 16-byte `struct in6_addr` on the stack, overflowing by up to 2016 bytes. Note that the main `radvd` daemon is not affected by the vulnerability. Version 2.21 patches the issue."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-48715\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-48715"
    ],
    "name": "CVE-2026-48715",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-10T21:52:32Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via heap buffer overwrite in Floyd-Steinberg dithering",
      "id": "2487759",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487759"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-124",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-24, when using an image with mask the Floyd-Steinberg dithering method it will cause a negative heap buffer over-write. This issue has been patched in version 7.1.2-24.",
      "A flaw was found in ImageMagick. When processing a specially crafted image that uses a mask with the Floyd-Steinberg dithering method, a negative heap buffer overwrite can occur. This vulnerability could allow an attacker to cause a denial of service (DoS) by crashing the application."
    ],
    "statement": "This Moderate impact vulnerability in ImageMagick arises from a heap buffer overwrite when processing a specially crafted image with a mask and the Floyd-Steinberg dithering method. Exploitation requires user interaction, as an attacker must convince a local user to process a malicious image. Successful exploitation leads to a denial of service by crashing the application.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-48724\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-48724\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2hhq-c99x-492r"
    ],
    "name": "CVE-2026-48724",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-29T00:00:00Z",
    "bugzilla": {
      "description": "curl: curl: Information disclosure due to incorrect TLS connection reuse",
      "id": "2461200",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461200"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-319",
    "details": [
      "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
      "A flaw was found in curl. A remote attacker could exploit this by initiating an unencrypted connection (via IMAP, SMTP, or POP3) and then making a subsequent request to the same host that requires Transport Layer Security (TLS). Due to incorrect connection reuse, the subsequent request would bypass the TLS requirement, leading to the transmission of sensitive information in cleartext. This vulnerability, categorized as Cleartext Transmission of Sensitive Information (CWE-319), results in information disclosure."
    ],
    "statement": "Moderate: This flaw in curl allows for information disclosure when an unencrypted connection is incorrectly reused for a subsequent request that expects TLS. This can lead to the cleartext transmission of sensitive data, potentially affecting Red Hat products that utilize curl for IMAP, SMTP, or POP3 connections where connection reuse is enabled.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:12916",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.20.0-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Fix deferred",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4873\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4873\nhttps://curl.se/docs/CVE-2026-4873.html"
    ],
    "name": "CVE-2026-4873",
    "mitigation": {
      "value": "To mitigate this issue, avoid using clear-text IMAP, POP3, or SMTP transfers with curl. Ensure that all connections for these protocols are initiated with TLS from the outset to prevent the reuse of unencrypted connections.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-10T21:53:35Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via crafted image in subimage-search",
      "id": "2487767",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487767"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-835",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, an infinite loop in the subimage-search operation can happen when using a crafted image. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.",
      "A flaw was found in ImageMagick. A remote attacker could exploit an infinite loop vulnerability in the subimage-search operation by providing a specially crafted image. This could lead to a Denial of Service (DoS) condition, making the affected system or application unresponsive."
    ],
    "statement": "This Moderate impact denial of service flaw in ImageMagick arises from an infinite loop during subimage-search operations when processing a specially crafted image. While exploitation requires a user to process a malicious image, successful attacks can lead to the affected system or application becoming unresponsive, impacting availability.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-48733\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-48733\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5v62-8fq6-cp9m"
    ],
    "name": "CVE-2026-48733",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-10T21:55:59Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via crafted MVG file leading to stack overflow",
      "id": "2487756",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487756"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-770",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result in a stack overflow due to a missing depth or visited-set check. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.",
      "A flaw was found in ImageMagick. A remote attacker could exploit this vulnerability by tricking a user into processing a specially crafted MVG (Magick Vector Graphics) file. This could lead to a stack overflow due to a missing depth or visited-set check, resulting in a denial of service (DoS) for the affected system."
    ],
    "statement": "This Moderate-severity flaw in ImageMagick requires user interaction, as an attacker must trick a user into processing a specially crafted MVG file. Successful exploitation could lead to a denial of service due to a stack overflow, impacting the availability of systems processing untrusted image data.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-48734\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-48734\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h36c-3666-h489"
    ],
    "name": "CVE-2026-48734",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-06T00:00:00Z",
    "bugzilla": {
      "description": "libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()",
      "id": "2451615",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451615"
    },
    "cvss3": {
      "cvss3_base_score": "6.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-367",
    "details": [
      "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.",
      "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation."
    ],
    "statement": "This is an Important flaw. A Time-of-Check-to-Time-of-Use (TOCTOU) race condition in libcap's cap_set_file() allows a local unprivileged user to escalate privileges. An attacker with write access to a parent directory can exploit a narrow window during file capability updates to redirect capabilities to an attacker-controlled file. This can lead to the injection of elevated privileges into an unintended executable when privileged processes, such as setcap or container tooling, invoke cap_set_file() on attacker-influenced paths.",
    "acknowledgement": "Red Hat would like to thank Ali Raza for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12423",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "libcap-0:2.69-7.el10_1.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19130",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libcap-0:2.69-7.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19456",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libcap-0:2.69-7.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-04T00:00:00Z",
        "advisory": "RHSA-2026:13285",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "libcap-0:2.48-6.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24346",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "libcap-0:2.48-4.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24346",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "libcap-0:2.48-4.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22957",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "libcap-0:2.48-5.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22957",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "libcap-0:2.48-5.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12441",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libcap-0:2.48-10.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19346",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libcap-0:2.48-10.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12441",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libcap-0:2.48-10.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19346",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libcap-0:2.48-10.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21254",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libcap-0:2.48-9.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20595",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "libcap-0:2.48-9.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19458",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libcap-0:2.48-9.el9_6.1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:26542",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202606160406-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:28887",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202606231112-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:23233",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202606030318-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-06-18T00:00:00Z",
        "advisory": "RHSA-2026:25044",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202606051757-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:34098",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202606250942-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:25181",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202606051320-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:23245",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202606031700-0"
      },
      {
        "product_name": "Cost Management Metrics Operator 4",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27998",
        "cpe": "cpe:/a:redhat:cost_management:4::el9",
        "package": "costmanagement/costmanagement-metrics-rhel9-operator:1780946239"
      },
      {
        "product_name": "Cost Management Metrics Operator 4",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39981",
        "cpe": "cpe:/a:redhat:cost_management:4::el9",
        "package": "costmanagement/costmanagement-metrics-rhel9-operator:1783539156"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30078",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1782352950"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30087",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1782352919"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30088",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1782353093"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30089",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1782352847"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14937",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1778101579"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14937",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1778156756"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7473",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libcap-main-2.78-1.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22634",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1780420428"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14162",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/opentelemetry-collector-rhel9:1778056267"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14162",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/opentelemetry-rhel9-operator:1778056233"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.9.3",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14162",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
        "package": "rhosdt/opentelemetry-target-allocator-rhel9:1778056245"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1779798159"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1779798164"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1779798165"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21275",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1779798222"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "compat-libcap1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libcap",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "compat-libcap1",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "libcap",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Under investigation",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4878\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4878\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2447554"
    ],
    "name": "CVE-2026-4878",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-19T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-48829\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-48829"
    ],
    "name": "CVE-2026-48829",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-26T18:53:04Z",
    "bugzilla": {
      "description": "libsolv: Stack-based buffer overflow in libsolv EdDSA PGP signature verification allows denial of service",
      "id": "2460975",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460975"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-121",
    "details": [
      "A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.",
      "A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows."
    ],
    "statement": "This is an Important memory-safety flaw in libsolv's PGP verification component, which can be triggered by specially crafted Ed25519 signatures. The vulnerability allows for a stack-based buffer overflow, potentially leading to a denial of service in automated package or repository processing workflows when verifying attacker-controlled signed content or metadata. This vulnerability doesn't affect any support Red Hat products as the vulnerable function is only compiled when `ENABLE_PUBKEY` configuration is enabled during build time. Such configuration option is disabled when the `libsolv` package is built for Red Hat Enterprise Linux versions, thus the affected code is not present in the final distributed binary.",
    "acknowledgement": "This issue was discovered by AISLE Research and AISLE in partnership with Red Hat.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "libsolv",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "libsolv",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "libsolv",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "libsolv",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "libsolv",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite-capsule:el8/libsolv",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Update Infrastructure 4 for Cloud Providers",
        "fix_state": "Not affected",
        "package_name": "libsolv",
        "cpe": "cpe:/a:redhat:rhui:4::el8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-48863\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-48863\nhttps://github.com/openSUSE/libsolv/commit/44f8c085045b1f771641091bbb2b810d12cff9e8#diff-309f245ec9b669ec78b8159c39e6f50130b4d4a0448f742685f7833d04bc4caaR592"
    ],
    "name": "CVE-2026-48863",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-26T11:35:00Z",
    "bugzilla": {
      "description": "gimp: GIMP:Memory disclosure and denial of service via specially crafted PCX image",
      "id": "2451669",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451669"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-193",
    "details": [
      "A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).",
      "A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS)."
    ],
    "statement": "Moderate: This flaw in GIMP's PCX file loader is due to a heap buffer over-read. Exploitation requires user interaction, specifically opening a specially crafted PCX image file. Red Hat Enterprise Linux systems are affected if GIMP is installed and used to open untrusted PCX files.",
    "acknowledgement": "Red Hat would like to thank Meshaal (@unrealmesh) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26168",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gimp-2:2.8.22-1.el7_9.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17533",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gimp:2.8-8100020260512115927.4c9c024f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20552",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gimp:2.8-8040020260520140422.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20552",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gimp:2.8-8040020260520140422.70584597"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20553",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gimp:2.8-8060020260520140100.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20553",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gimp:2.8-8060020260520140100.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20553",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gimp:2.8-8060020260520140100.6af1eaf0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20554",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gimp:2.8-8080020260520102644.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20554",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gimp:2.8-8080020260520102644.0621e4ee"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16484",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-1.el9_7.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19362",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gimp-2:3.0.4-4.el9_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20691",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gimp-2:2.99.8-3.el9_0.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25899",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gimp-2:2.99.8-4.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25907",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gimp-2:2.99.8-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-15T00:00:00Z",
        "advisory": "RHSA-2026:25901",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gimp-2:2.99.8-4.el9_6.7"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gimp",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4887\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4887\nhttps://gitlab.gnome.org/GNOME/gimp/-/issues/15960"
    ],
    "name": "CVE-2026-4887",
    "mitigation": {
      "value": "Users should avoid opening untrusted PCX image files with GIMP. If GIMP is not required, consider removing the `gimp` package to eliminate this attack vector.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-09T00:00:00Z",
    "bugzilla": {
      "description": "dnsmasq: NSEC bitmap parsing infinite loop",
      "id": "2458516",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458516"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-835",
    "details": [
      "A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.",
      "A denial of service vulnerability was discovered in dnsmasq's DNSSEC validation. When parsing NSEC and NSEC3 bitmap records, the window iteration logic fails to account for the 2-byte window header when advancing through the bitmap data. A specially crafted DNS response with a zero-length bitmap can cause an infinite loop, making dnsmasq unresponsive to all queries."
    ],
    "statement": "This issue affects deployments with DNSSEC validation enabled (--dnssec). The flaw is reachable before RRSIG signature validation, meaning no valid DNSSEC signatures are required to trigger it. However, the primary impact is limited to denial of service.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19158",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "dnsmasq-0:2.90-7.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20589",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "dnsmasq-0:2.79-36.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19373",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "dnsmasq-0:2.85-18.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34508",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "dnsmasq-0:2.85-17.el9_6.1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:40762",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202607151909-0"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Under investigation",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Under investigation",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4890\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4890\nhttps://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html"
    ],
    "name": "CVE-2026-4890",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-09T00:00:00Z",
    "bugzilla": {
      "description": "dnsmasq: RRSIG rdlen underflow leading to heap OOB read",
      "id": "2458517",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458517"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.",
      "A heap out-of-bounds read vulnerability was discovered in dnsmasq's DNSSEC validation. When processing RRSIG records, dnsmasq calculates the signature length by subtracting the fixed field size from the record's declared data length. A crafted RRSIG record with a data length smaller than the fixed fields causes this calculation to underflow, potentially resulting in an out-of-bounds read and process crash."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19158",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "dnsmasq-0:2.90-7.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20589",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "dnsmasq-0:2.79-36.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19373",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "dnsmasq-0:2.85-18.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34508",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "dnsmasq-0:2.85-17.el9_6.1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:40762",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202607151909-0"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4891\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4891\nhttps://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html"
    ],
    "name": "CVE-2026-4891",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-09T00:00:00Z",
    "bugzilla": {
      "description": "dnsmasq: DHCPv6 CLID buffer overflow in helper process",
      "id": "2458518",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458518"
    },
    "cvss3": {
      "cvss3_base_score": "8.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-122",
    "details": [
      "A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.",
      "A heap buffer overflow was discovered in dnsmasq's DHCP script helper process. When processing DHCPv6 client identifiers (CLIDs), the helper hex-encodes the raw CLID bytes into a fixed-size buffer without length validation. Since DHCPv6 CLIDs can be up to 65,535 bytes, a crafted DHCPv6 packet can overflow the buffer with attacker-controlled content. The helper process runs with root privileges."
    ],
    "statement": "Red Hat rates this as Important. The overflow occurs in a root-privileged helper process with attacker-controlled content, and the `--dhcp-script` option is enabled by default in libvirt virtual network configurations, which affects RHEL systems using virt-manager, virt-install, or cockpit-machines. Exploitation requires the attacker to send crafted DHCPv6 packets from within the virtual network, meaning a malicious VM guest could potentially exploit this for host-level code execution as root.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19158",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "dnsmasq-0:2.90-7.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20589",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "dnsmasq-0:2.79-36.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19373",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "dnsmasq-0:2.85-18.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34508",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "dnsmasq-0:2.85-17.el9_6.1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:40762",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202607151909-0"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4892\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4892\nhttps://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html"
    ],
    "name": "CVE-2026-4892",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-09T00:00:00Z",
    "bugzilla": {
      "description": "dnsmasq: Broken ECS source validation bypass",
      "id": "2458519",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458519"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-20",
    "details": [
      "An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.",
      "A validation bypass was discovered in dnsmasq's RFC 7871 client subnet (ECS) handling. When verifying ECS source information in DNS responses, dnsmasq passes the OPT record length instead of the full packet length to the validation function.This causes all internal bounds checks to fail, completely bypassing ECS source validation and allowing an attacker to spoof client subnet information."
    ],
    "statement": "Red Hat rates this as Moderate. This issue affects deployments with the `--add-subnet` option enabled. The impact is limited to bypassing ECS source validation, which could allow cache manipulation scoped to specific subnets or minor information disclosure about network topology.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19158",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "dnsmasq-0:2.90-7.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20589",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "dnsmasq-0:2.79-36.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19373",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "dnsmasq-0:2.85-18.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34508",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "dnsmasq-0:2.85-17.el9_6.1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:40762",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202607151909-0"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "dnsmasq",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-4893\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4893\nhttps://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html"
    ],
    "name": "CVE-2026-4893",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-27T03:12:38Z",
    "bugzilla": {
      "description": "perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob",
      "id": "2481767",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481767"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-94",
    "details": [
      "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\nArbitrary Perl in the output glob executes at the calling process's privilege.",
      "A flaw was found in perl-IO-Compress, a component used for data compression and decompression. A remote attacker could exploit this vulnerability by crafting a malicious input, specifically an output glob, that bypasses the intended security measures. This could lead to the execution of unauthorized code on the system, potentially allowing the attacker to take full control of the affected process."
    ],
    "statement": "This is an Important severity flaw in `perl-IO-Compress` that allows arbitrary code execution. A remote attacker can exploit a vulnerability in the `File::GlobMapper` component by providing a specially crafted output glob. This can lead to the execution of arbitrary Perl code with the privileges of the affected process, potentially compromising the system.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30860",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "perl-IO-Compress-0:2.212-512.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29941",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "perl-IO-Compress-0:2.212-512.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30843",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "perl-IO-Compress-0:2.061-2.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30851",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "perl:5.32-8100020260616084412.651ee29f"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30858",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "perl-IO-Compress-0:2.081-2.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29867",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "perl-IO-Compress-0:2.081-1.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29867",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "perl-IO-Compress-0:2.081-1.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30115",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "perl-IO-Compress-0:2.081-1.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30115",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "perl-IO-Compress-0:2.081-1.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50262",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "perl:5.32-8080020260622152847.3ba2f806"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30086",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "perl-IO-Compress-0:2.081-1.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50262",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "perl:5.32-8080020260622152847.3ba2f806"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30086",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "perl-IO-Compress-0:2.081-1.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30859",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "perl-IO-Compress-0:2.102-4.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29210",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "perl-IO-Compress-0:2.102-4.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29182",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "perl-IO-Compress-0:2.102-4.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-26T00:00:00Z",
        "advisory": "RHSA-2026:30085",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "perl-IO-Compress-0:2.102-4.el9_6.1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-48962\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-48962\nhttps://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch\nhttps://metacpan.org/release/PMQS/IO-Compress-2.220/changes"
    ],
    "name": "CVE-2026-48962",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-10T21:59:04Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via crafted DCM image with invalid dimensions",
      "id": "2487763",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487763"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1284",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operation. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.",
      "A flaw was found in ImageMagick. A missing check in the DCM (Digital Imaging and Communications in Medicine) decoder allows a remote attacker to provide a specially crafted image with invalid dimensions. This can lead to crashes in other operations, resulting in a denial of service (DoS) for the application processing the image."
    ],
    "statement": "```\nIt is important to note that ImageMagick has been removed from Red Hat Enterprise Linux 8 and later releases. Therefore, current supported RHEL 8 and newer systems are not affected by this issue unless ImageMagick is installed from third-party or custom repositories.\nFor additional information, refer to https://access.redhat.com/solutions/4437561.\n```",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32961",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "ImageMagick-0:6.9.10.68-17.el7_9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-49218\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-49218\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8pj9-6897-74xc"
    ],
    "name": "CVE-2026-49218",
    "mitigation": {
      "value": "Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-10T22:00:26Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Information disclosure via incorrect filename parsing",
      "id": "2487752",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487752"
    },
    "cvss3": {
      "cvss3_base_score": "4.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-59",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.",
      "A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. An attacker with local access could exploit an incorrect parsing of filenames to bypass security policies. This could allow the attacker to read files that are otherwise disallowed by the system's security configuration, leading to information disclosure."
    ],
    "statement": "This flaw in ImageMagick is rated as Low impact. It allows an attacker with local access and high privileges to bypass security policies through incorrect filename parsing. This could lead to the disclosure of files that are otherwise protected by the system's security configuration.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-49219\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-49219\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xcjm-wqff-m669"
    ],
    "name": "CVE-2026-49219",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-09T14:04:07Z",
    "bugzilla": {
      "description": "elixir: Elixir Version module: Denial of Service via uncontrolled resource consumption with crafted version string",
      "id": "2487016",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487016"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-770",
    "details": [
      "Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allows an attacker who controls a version string to cause a denial of service through CPU and memory exhaustion.\nThe version parser converts numeric version components (major, minor, patch and numeric pre-release/build identifiers) to integers without bounding their length. A single large all-digit component therefore forces a super-linear, non-yielding base-10 to arbitrary-precision integer conversion (String.to_integer/1, i.e. :erlang.binary_to_integer/1) that pins a BEAM scheduler, and a larger component raises an uncaught SystemLimitError that crashes the calling process. A single moderately sized string (around one megabyte) is enough; no authentication is required.\nThis is reachable from the public entry points Version.parse/1, Version.parse!/1, Version.match?/3, Version.compare/2, and Version.parse_requirement/1, which applications routinely call on untrusted input such as HTTP parameters, dependency-manifest fields, and package metadata.\nThis vulnerability is associated with program files lib/version.ex and program routines 'Elixir.Version.Parser':parse_digits/2.\nThis issue affects Elixir: from 1.5.0 before 1.20.1.",
      "A flaw was found in the Elixir standard library's Version module. A remote attacker can exploit this uncontrolled resource consumption vulnerability by providing a specially crafted, excessively long version string. This malicious input forces the system to perform a super-linear, arbitrary-precision integer conversion, leading to significant CPU and memory exhaustion. The primary consequence is a Denial of Service (DoS), which can pin a BEAM scheduler or crash the affected process."
    ],
    "package_state": [
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "elixir",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "elixir",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "elixir",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-49762\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-49762\nhttps://cna.erlef.org/cves/CVE-2026-49762.html\nhttps://github.com/elixir-lang/elixir/commit/c64417d72fd5c7d09e963ca3ac5fa2b140978d9e\nhttps://github.com/elixir-lang/elixir/security/advisories/GHSA-w2h8-8x3g-278p\nhttps://osv.dev/vulnerability/EEF-CVE-2026-49762"
    ],
    "name": "CVE-2026-49762",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-03T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "lxml_html_clean.Cleaner does not strip javascript: URLs from namespaced URL attributes (xlink:href). The vulnerability exists because Cleaner filters URL schemes by walking links via rewrite_links(), which delegates to iterlinks(), which only yields attributes named in lxml.html.defs.link_attrs. That allow-list contains no prefixed names such as xlink:href. As a result, when Cleaner is configured with safe_attrs_only=False, an xlink:href attribute carrying a javascript: URL survives sanitization untouched, and any browser that follows the SVG or MathML anchor specification will execute the JavaScript when the rendered link is clicked, leading to Cross-Site Scripting (XSS) attacks."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-49825\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-49825"
    ],
    "name": "CVE-2026-49825",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-25T17:17:46Z",
    "bugzilla": {
      "description": "jq: jq: Heap out-of-bounds write via oversized raw file processing",
      "id": "2493020",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493020"
    },
    "cvss3": {
      "cvss3_base_score": "6.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv_invalid_with_msg(\"String too long\"), the raw-file loop does not stop. If the file contains at least one more byte, the next loop iteration appends a new chunk to an object that is already invalid. With assertions enabled this aborts in jvp_string_ptr(). With assertions disabled, the invalid object is interpreted as a string object and ASan reports heap-buffer-overflow. This vulnerability is fixed in 1.8.2.",
      "A flaw was found in jq, a command-line JSON processor. This vulnerability allows an attacker to trigger a heap out-of-bounds write by providing a specially crafted, oversized file to the `jq --rawfile` option. This can lead to a denial of service (DoS), making the affected system or application unavailable, and may also impact data integrity. Exploitation requires user interaction, as a user must process the malicious file."
    ],
    "statement": "A flaw was found in jq, a command-line JSON processor. When using the `--rawfile` option to process an oversized file, jq can trigger a heap out-of-bounds write in assertion-disabled builds (typical for release builds). Exploitation requires a local user to explicitly process an attacker-controlled file. With assertions enabled, the process aborts instead of corrupting memory.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29986",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-49839\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-49839\nhttps://github.com/jqlang/jq/security/advisories/GHSA-cfh2-vwfq-qfmm"
    ],
    "name": "CVE-2026-49839",
    "mitigation": {
      "value": "Avoid using `jq --rawfile` with untrusted or user-controlled files.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-03T00:00:00Z",
    "bugzilla": {
      "description": "httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack",
      "id": "2485371",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485371"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-409",
    "details": [
      "Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.\nThis issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.",
      "A flaw was found in HTTP/2, affecting various web servers. A remote attacker can exploit this vulnerability by combining an HPACK compression bomb with a zero-byte flow-control window. This technique allows a small amount of data to expand into large memory allocations on the server, which are then held, leading to a denial of service (DoS) by rendering the server inaccessible."
    ],
    "statement": "The Apache's `httpd` HTTP/2 protocol implementation has a denial-of-service (DoS) vulnerability that is rated as Important. An unauthenticated remote attacker can exploit this flaw by combining HPACK compression with flow control manipulation, leading to significant server memory exhaustion and rendering the service inaccessible. This vulnerability exists in default HTTP/2 configurations.",
    "affected_release": [
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services for RHEL 8",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el8",
        "package": "jbcs-httpd24-mod_http2-0:2.0.29-10.el8jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-httpd-0:2.4.62-13.el7jbcs"
      },
      {
        "product_name": "JBoss Core Services on RHEL 7",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27200",
        "cpe": "cpe:/a:redhat:jboss_core_services:1::el7",
        "package": "jbcs-httpd24-mod_http2-0:2.0.29-10.el7jbcs"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25225",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "mod_http2-0:2.0.29-4.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50538",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "mod_http2-0:2.0.29-2.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25090",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "httpd:2.4-8100020260608081321.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36846",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "httpd:2.4-8040020260702193120.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36846",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "httpd:2.4-8040020260702193120.522a0ee4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36831",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "httpd:2.4-8060020260702195216.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36831",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "httpd:2.4-8060020260702195216.ad008a3a"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36373",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "httpd:2.4-8080020260702200145.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36373",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "httpd:2.4-8080020260702200145.63b34585"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25057",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "mod_http2-0:2.0.26-6.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:55930",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "mod_http2-0:1.15.19-4.el9_2.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:55992",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "mod_http2-0:2.0.26-2.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50572",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "mod_http2-0:2.0.26-4.el9_6.2"
      },
      {
        "product_name": "Red Hat JBoss Core Services 2.4.62.SP4",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27201",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "jbcs-httpd24-httpd"
      },
      {
        "product_name": "Red Hat JBoss Core Services 2.4.62.SP4",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:27201",
        "cpe": "cpe:/a:redhat:jboss_core_services:1",
        "package": "jbcs-httpd24-mod_http2"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25042",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "httpd-main-2.4.68-1.hum1"
      },
      {
        "product_name": "Red Hat OpenShift Service Mesh 2.6",
        "release_date": "2026-06-18T00:00:00Z",
        "advisory": "RHSA-2026:27114",
        "cpe": "cpe:/a:redhat:service_mesh:2.6::el9",
        "package": "openshift-service-mesh/proxyv2-rhel9:1781604724"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-apache-commons-daemon",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-apache-commons-daemon-jsvc",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-apr",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-apr-util",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-brotli",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-compose",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-curl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-dist",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-jansson",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-mod_cluster-native",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-mod_jk",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-mod_md",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-mod_proxy_cluster",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-mod_security",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-nghttp2",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-openssl-chil",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-openssl-pkcs11",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-apr",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Not affected",
        "package_name": "jbcs-httpd24-openssl",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-49975\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-49975\nhttps://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb"
    ],
    "name": "CVE-2026-49975",
    "mitigation": {
      "value": "See the security bulletin for a detailed mitigation procedure.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-23T00:00:00Z",
    "bugzilla": {
      "description": "squid: memory corruption in cache_digest reply handling",
      "id": "2492883",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492883"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-122",
    "details": [
      "Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the mask_size declared within the digest, so a trusted peer sending a maliciously crafted reply to a cache_digest request message can trigger the overflow. This attack is limited to Squid instances compiled with the --enable-cache-digests option and configured with cache_peer entries. This issue is fixed in version 7.6.",
      "A flaw was found in Squid. Due to improper input validation, a heap-based buffer overflow can occur when processing cache digests. This issue allows a trusted server to cause a denial of service when sending specially crafted replies to cache_digest request messages."
    ],
    "statement": "To exploit this issue, an attacker must control a trusted cache peer server. Also, cache digests are not enabled in the default configuration. Squid deployments that do not use cache peering are not affected. Furthermore, even those that do are only vulnerable when the attacker controls a configured peer server within the same administrative domain. A compromised peer can reliably crash the Squid process via a heap-based buffer overflow during digest exchange, but code execution faces considerable practical security barriers.\nDefault Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability.\nDue to these reasons, this vulnerability has been rated with a moderate severity.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "squid34",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "squid:4/squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "squid",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50012\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50012\nhttps://github.com/squid-cache/squid/security/advisories/GHSA-5vmx-9x64-9284"
    ],
    "name": "CVE-2026-50012",
    "mitigation": {
      "value": "To mitigate this vulnerability, restrict or disable cache digest processing for cache peers by adding the appropriate settings to the squid.conf configuration file:\nDisable cache digests for any cache_peer not under direct control by adding the no-digest option. This completely removes the vulnerability for those peers at the cost of increased bandwidth. Use of HTCP or ICP as alternative protocols can reduce that cost.\n~~~\n# Example of disabling digests for an untrusted peer.\ncache_peer untrusted.server.example.com parent 3128 3130 no-digest\n~~~\nAudit the Squid configuration and ensure that all configured cache_peer entries are under direct control and are trusted. Restricting cache peering exclusively to trusted domains greatly reduces the risk of exploitation.\n~~~\n# Example of a fully trusted peer without the no-digest flag.\ncache_peer trusted.internal.example.com parent 3128 3130\n~~~",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-03T03:07:25Z",
    "bugzilla": {
      "description": "freeipmi: FreeIPMI: Denial of service via buffer overflow in ipmi-oem client",
      "id": "2484296",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484296"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands \"ipmi-oem dell get-active-directory-config\" and \"ipmi-oem fujitsu get-sel-entry-long-text\" were found to have exploitable buffer overflows on response messages.",
      "A flaw was found in FreeIPMI. Specifically, the `ipmi-oem` client command, which implements Intelligent Platform Management Interface (IPMI) OEM commands, contains exploitable buffer overflows. A remote attacker could exploit these vulnerabilities by sending specially crafted response messages to the `ipmi-oem` client, leading to a denial of service (DoS) condition and making the system unavailable."
    ],
    "statement": "This issue was classified as Moderate. It is an application level denial of service flaw in FreeIPMI's `ipmi-oem` client. A remote attacker can exploit buffer overflows by sending specially crafted response messages to the `ipmi-oem` client, leading to system unavailability. This vulnerability requires the `ipmi-oem` command to be actively used with specific OEM subcommands to communicate with a malicious or compromised Intelligent Platform Management Interface (IPMI) server.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36211",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "freeipmi-0:1.6.18-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:39007",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "freeipmi-0:1.6.14-4.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48826",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "freeipmi-0:1.5.7-3.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36307",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "freeipmi-0:1.6.18-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50729",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "freeipmi-0:1.6.6-1.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50729",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "freeipmi-0:1.6.6-1.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50772",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "freeipmi-0:1.6.8-1.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50772",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "freeipmi-0:1.6.8-1.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50769",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "freeipmi-0:1.6.8-1.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50769",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "freeipmi-0:1.6.8-1.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36210",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "freeipmi-0:1.6.18-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:39010",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "freeipmi-0:1.6.14-2.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:39008",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "freeipmi-0:1.6.14-2.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:39006",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "freeipmi-0:1.6.14-2.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "freeipmi",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50031\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50031\nhttps://lists.gnu.org/archive/html/info-gnu/2026-06/msg00000.html\nhttps://savannah.gnu.org/bugs/index.php?68363\nhttps://savannah.gnu.org/bugs/index.php?68364"
    ],
    "name": "CVE-2026-50031",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-04T04:20:32Z",
    "bugzilla": {
      "description": "expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking",
      "id": "2484620",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484620"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-911",
    "details": [
      "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
      "A flaw was found in libexpat. This vulnerability occurs because the library, in versions before 2.8.2, does not properly track handler call depth when certain XML parsing functions are invoked from within handlers during a policy violation. This oversight can lead to a use-after-free condition, which may result in information disclosure, integrity loss, or denial of service."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-28T00:00:00Z",
        "advisory": "RHSA-2026:30647",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "expat-main-2.8.2-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "compat-expat1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50219\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50219\nhttps://github.com/libexpat/libexpat/pull/1246"
    ],
    "name": "CVE-2026-50219",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-29T20:36:24Z",
    "bugzilla": {
      "description": "tomcat: Apache Tomcat: Cross-Site Scripting vulnerability in number guess example",
      "id": "2494688",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494688"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-79",
    "details": [
      "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.",
      "A flaw was found in Apache Tomcat. This vulnerability, known as Cross-Site Scripting (XSS), allows a remote attacker to inject malicious scripts into the 'number guess example' web page. When other users view the compromised page, these scripts can execute in their web browsers. This could lead to unauthorized access to sensitive information or allow an attacker to alter the content of the website."
    ],
    "statement": "A flaw was found in Apache Tomcat. A Cross-Site Scripting (XSS) vulnerability exists in the \"number guess\" example web application shipped with Tomcat. An attacker can inject malicious scripts into the example page, which execute in other users' browsers when they view the page. This vulnerability only affects the example web application, not the Tomcat servlet container itself. Red Hat Tomcat packages do not deploy example applications by default — they are in separate optional packages (e.g., tomcat-webapps) that are not installed in production environments.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32960",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.23-0.1.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "tomcat10",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Fix deferred",
        "package_name": "jws5-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Not affected",
        "package_name": "tomcat-websocket",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7",
        "fix_state": "Not affected",
        "package_name": "tomcat-websocket",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50229\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50229\nhttps://lists.apache.org/thread/wlt2no8bw45zl1w8byop4zfqphldf5j0"
    ],
    "name": "CVE-2026-50229",
    "mitigation": {
      "value": "Remove or disable the Tomcat example web applications if they are deployed. Example applications are not needed for production use and should not be accessible in production environments.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-07-22T13:08:21Z",
    "bugzilla": {
      "description": "unbound: Unbound: Insecure DNS redirection via spoofed DNS answers",
      "id": "2506132",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506132"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-348",
    "details": [
      "In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting handler does not check the security status of the upstream answer and can instead rewrite a BOGUS A/AAAA answer to point to an operator's configured IP. If the validator finds an expired or otherwise invalid RRSIG on an answer whose A record falls within a 'response-ip'/RPZ configuration, the answer is still rewritten and given a hard coded security level of INSECURE. This results in the client receiving an INSECURE NOERROR reply rewritten by the operator's configured IP. A malicious actor can exploit the possible poisonous effect by spoofing a BOGUS A/AAAA answer that falls inside the operator's configured subnet rewrites. Such DNSSEC protected answers are then insecurely redirected to the operator's configured target.",
      "A flaw in Unbound's respip module fails to verify the security status of incoming DNS answers when using response-ip rules or RPZ files. A remote attacker can exploit this by spoofing DNS answers to bypass DNSSEC protections and trigger unauthorized rewrites, redirecting clients to unintended locations."
    ],
    "statement": "This vulnerability has a Low impact because it requires Unbound to be specifically configured with the 'respip' module and either a 'response-ip' redirect rule or an RPZ file. This non-default setup allows a remote attacker to spoof DNS answers, resulting in the insecure redirection of DNSSEC protected responses.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43588",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "unbound-main-1.25.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50243\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50243\nhttps://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50243.txt"
    ],
    "name": "CVE-2026-50243",
    "mitigation": {
      "value": "If IP-based rewriting is unused, leave module-config configured as \"validator iterator\" and do not configure response-ip redirects or RPZ-IP triggers. If these features are required, ensure validator is placed before respip in module-config and restrict upstream peer access to reduce exposure to spoofed DNS answers.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-22T13:08:32Z",
    "bugzilla": {
      "description": "unbound: Unbound: DNS response policy replacement via hostname spoofing",
      "id": "2506129",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506129"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-345",
    "details": [
      "In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.",
      "A flaw in Unbound allows a remote attacker to replace an authenticated or Response Policy Zone (RPZ) by spoofing DNS records for configured primary hostnames. This enables the attacker to impersonate the primary server, leading to DNS cache poisoning or traffic redirection."
    ],
    "statement": "A Moderate impact flaw in Unbound allows a remote attacker to replace a resolver's Response Policy Zone (RPZ) by spoofing A/AAAA records for configured primary hostnames. If successful, an attacker can manipulate response policies, redirect traffic, or poison the DNS cache.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43588",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "unbound-main-1.25.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50248\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50248\nhttps://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50248.txt"
    ],
    "name": "CVE-2026-50248",
    "mitigation": {
      "value": "Configure Response Policy Zones (RPZ) and secondary zone primary endpoints using explicit IP addresses rather than hostnames to prevent A/AAAA spoofing or resolution flaws. Additionally, restrict network access for zone transfers to trusted sources and reload or restart the unbound service for configuration changes to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-22T13:08:43Z",
    "bugzilla": {
      "description": "unbound: NLnet Labs Unbound: Denial of Service via crafted DNS glue records",
      "id": "2506150",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506150"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-835",
    "details": [
      "In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies since the remote IP does not match the original source IP of 0.0.0.0/::0. This behavior keeps on looping for the glue records and pushing the counter to the configured 'unwanted-reply-threshold' that triggers a defensive cache clear. A malicious actor who controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0 can drive the counter to the limit of 'unwanted-reply-threshold' to the threshold and trigger a cache clean of the message and rrset caches; at will, indefinitely, without sending a single spoofed packet. The iterator uses the 0.0.0.0/::0 glue, and a system that can route this (e.g., Linux kernel routes the datagram over loopback), Unbound's own listener answers from 127.0.0.1. Because of the mismatch of 0.0.0.0 and 127.0.0.1, in this example, Unbound accounts the reply as an unwanted (probably spoofed) answer. The counter resets to zero on every cache flush, so the attack loops forever.",
      "A flaw was found in Unbound. A remote malicious actor can exploit a vulnerability by controlling a DNS delegation that returns specific glue records. This can cause Unbound to repeatedly clear its DNS caches, leading to a continuous Denial of Service (DoS) for DNS resolution."
    ],
    "statement": "This Moderate flaw in Unbound allows a remote attacker to trigger a denial of service by controlling a DNS delegation. When the `unwanted-reply-threshold` option is enabled, specially crafted glue records can cause Unbound to repeatedly clear its DNS caches, disrupting DNS resolution. This occurs due to Unbound's internal handling of locally routed 0.0.0.0/::0 glue records, which are incorrectly flagged as unwanted replies.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43588",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "unbound-main-1.25.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50251\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50251\nhttps://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50251.txt"
    ],
    "name": "CVE-2026-50251",
    "mitigation": {
      "value": "To mitigate this issue, configure Unbound to disable the `unwanted-reply-threshold` option by setting it to `0` in the `unbound.conf` file. This prevents the cache clearing behavior triggered by malicious glue records. After modifying the configuration, restart the Unbound service for the changes to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-02T00:00:00Z",
    "bugzilla": {
      "description": "xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch",
      "id": "2485380",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485380"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-121",
    "details": [
      "A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.",
      "A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root."
    ],
    "statement": "Red Hat rates this issue as Important impact. In xorg-x11-server and xorg-x11-server-Xwayland, the X server allocates a 256-byte stack buffer for font alias resolution but libXfont2 permits alias target names up to 1024 bytes. A local X client requesting a font alias between 257 and 1023 bytes triggers a stack buffer overflow. Any local user who can connect to the X server display can attempt exploitation. This may crash the display server or, where the X server runs with elevated privileges, could contribute to local privilege escalation. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.",
    "acknowledgement": "Upstream acknowledges Anonymous (Trend Micro Zero Day Initiative) as the original reporter.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:26566",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36798",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49519",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "tigervnc-0:1.1.0-25.el6_10.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36083",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-35.el7_9",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46473",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26562",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26709",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-0:1.20.11-28.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:28923",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "tigervnc-0:1.15.0-10.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26590",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26610",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-34.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29844",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-7.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36086",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-21.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36633",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46377",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36087",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-0:1.20.11-29.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36632",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46456",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36085",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-34.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36634",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46392",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-11.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "important"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50256\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50256\nhttps://gitlab.freedesktop.org/xorg/xserver/-/commit/bb5158f962dc935e58ef8b4b5fcb31be201a6e07\nhttps://lists.x.org/archives/xorg-announce/2026-June/003702.html\nhttps://redhat.atlassian.net/browse/PSIRTSUPT-16950"
    ],
    "name": "CVE-2026-50256",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-02T00:00:00Z",
    "bugzilla": {
      "description": "xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence()",
      "id": "2485382",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485382"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-416",
    "details": [
      "A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.",
      "A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root."
    ],
    "statement": "Red Hat rates this issue as Important impact. In xorg-x11-server and xorg-x11-server-Xwayland, a local X client can trigger a use-after-free function pointer call in miSyncDestroyFence() by setting up a fence trigger on one connection and destroying the fence from a second connection. Any local user who can connect to the X server display can attempt exploitation. This may crash the display server or, where the X server runs with elevated privileges, could contribute to local privilege escalation. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.",
    "acknowledgement": "Upstream acknowledges Anonymous (Trend Micro Zero Day Initiative) as the original reporter.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:26566",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36798",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49519",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "tigervnc-0:1.1.0-25.el6_10.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36083",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-35.el7_9",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46473",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26562",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26709",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-0:1.20.11-28.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:28923",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "tigervnc-0:1.15.0-10.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26590",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26610",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-34.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29844",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-7.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36086",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-21.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36633",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46377",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36087",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-0:1.20.11-29.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36632",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46456",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36085",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-34.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36634",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46392",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-11.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "important"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50257\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50257\nhttps://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b\nhttps://lists.x.org/archives/xorg-announce/2026-June/003702.html\nhttps://redhat.atlassian.net/browse/PSIRTSUPT-16950"
    ],
    "name": "CVE-2026-50257",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-02T00:00:00Z",
    "bugzilla": {
      "description": "xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels",
      "id": "2485383",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485383"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-121",
    "details": [
      "A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.",
      "A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root."
    ],
    "statement": "Red Hat rates this issue as Important impact. In xorg-x11-server and xorg-x11-server-Xwayland, CheckKeyTypes() does not clamp non-canonical keyboard types to XkbMaxShiftLevel. A local X client can set excessive shift levels and trigger stack buffer overflows in multiple code paths. This is an incomplete fix of CVE-2025-26597. Any local user who can connect to the X server display can attempt exploitation. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.",
    "acknowledgement": "Upstream acknowledges Anonymous (Trend Micro Zero Day Initiative) as the original reporter.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:26566",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36798",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49519",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "tigervnc-0:1.1.0-25.el6_10.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36083",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-35.el7_9",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46473",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26562",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26709",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-0:1.20.11-28.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:28923",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "tigervnc-0:1.15.0-10.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26590",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26610",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-34.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29844",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-7.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36086",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-21.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36633",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46377",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36087",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-0:1.20.11-29.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36632",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46456",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36085",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-34.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36634",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46392",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-11.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "important"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50258\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50258\nhttps://gitlab.freedesktop.org/xorg/xserver/-/commit/543e108516428fc8c3bea91d6563ad266f9a801e\nhttps://lists.x.org/archives/xorg-announce/2026-June/003702.html\nhttps://redhat.atlassian.net/browse/PSIRTSUPT-16950"
    ],
    "name": "CVE-2026-50258",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-02T00:00:00Z",
    "bugzilla": {
      "description": "xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing",
      "id": "2485384",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485384"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-121",
    "details": [
      "A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.",
      "A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root."
    ],
    "statement": "Red Hat rates this issue as Important impact. In xorg-x11-server and xorg-x11-server-Xwayland, _XkbSetMapChecks() uses a fixed 256-element stack buffer mapWidths[] indexed by a client-controlled key type index. CheckKeyTypes() writes beyond the buffer boundary, causing a stack buffer overflow. Any local user who can connect to the X server display can attempt exploitation. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.",
    "acknowledgement": "Upstream acknowledges Anonymous (Trend Micro Zero Day Initiative) as the original reporter.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:26566",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36798",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49519",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "tigervnc-0:1.1.0-25.el6_10.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36083",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-35.el7_9",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46473",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26562",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26709",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-0:1.20.11-28.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:28923",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "tigervnc-0:1.15.0-10.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26590",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26610",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-34.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29844",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-7.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36086",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-21.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36633",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46377",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36087",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-0:1.20.11-29.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36632",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46456",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36085",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-34.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36634",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46392",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-11.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "important"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50259\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50259\nhttps://gitlab.freedesktop.org/xorg/xserver/-/commit/867b59b33bee669cb412f1314e47c52eacf6e00b\nhttps://lists.x.org/archives/xorg-announce/2026-June/003702.html\nhttps://redhat.atlassian.net/browse/PSIRTSUPT-16950"
    ],
    "name": "CVE-2026-50259",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-02T00:00:00Z",
    "bugzilla": {
      "description": "xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter()",
      "id": "2485385",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485385"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-416",
    "details": [
      "A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.",
      "A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root."
    ],
    "statement": "Red Hat rates this issue as Important impact. In xorg-x11-server and xorg-x11-server-Xwayland, a local X client can trigger a use-after-free in FreeCounter() by creating SyncCounters and awaiting triggers on one connection while destroying those counters from a second connection. Any local user who can connect to the X server display can attempt exploitation. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.",
    "acknowledgement": "Upstream acknowledges Anonymous (Trend Micro Zero Day Initiative) as the original reporter.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:26566",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36798",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49519",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "tigervnc-0:1.1.0-25.el6_10.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36083",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-35.el7_9",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46473",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26562",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26709",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-0:1.20.11-28.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:28923",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "tigervnc-0:1.15.0-10.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26590",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26610",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-34.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29844",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-7.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36086",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-21.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36633",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46377",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36087",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-0:1.20.11-29.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36632",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46456",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36085",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-34.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36634",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46392",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-11.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "important"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50260\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50260\nhttps://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b\nhttps://lists.x.org/archives/xorg-announce/2026-June/003702.html\nhttps://redhat.atlassian.net/browse/PSIRTSUPT-16950"
    ],
    "name": "CVE-2026-50260",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-02T00:00:00Z",
    "bugzilla": {
      "description": "xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter()",
      "id": "2485386",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485386"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-416",
    "details": [
      "A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.",
      "A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root."
    ],
    "statement": "Red Hat rates this issue as Important impact. In xorg-x11-server and xorg-x11-server-Xwayland, a local X client can trigger a use-after-free in SyncChangeCounter() by creating SyncCounters on one connection while changing and destroying them from a second connection. Any local user who can connect to the X server display can attempt exploitation. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.",
    "acknowledgement": "Upstream acknowledges Anonymous (Trend Micro Zero Day Initiative) as the original reporter.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:26566",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36798",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49519",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "tigervnc-0:1.1.0-25.el6_10.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36083",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-35.el7_9",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46473",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26562",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26709",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-0:1.20.11-28.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:28923",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "tigervnc-0:1.15.0-10.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26590",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26610",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-34.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29844",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-7.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36086",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-21.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36633",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46377",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36087",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-0:1.20.11-29.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36632",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46456",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36085",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-34.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36634",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46392",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-11.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "important"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50261\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50261\nhttps://gitlab.freedesktop.org/xorg/xserver/-/commit/bdd7bf57af208b1ddf57d4683d67104443b44812\nhttps://lists.x.org/archives/xorg-announce/2026-June/003702.html\nhttps://redhat.atlassian.net/browse/PSIRTSUPT-16950"
    ],
    "name": "CVE-2026-50261",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-02T00:00:00Z",
    "bugzilla": {
      "description": "xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes",
      "id": "2485387",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485387"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.",
      "An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default."
    ],
    "statement": "Red Hat rates this issue as Moderate impact. In xorg-x11-server and xorg-x11-server-Xwayland, __glXDisp_ChangeDrawableAttributes() validates request size incorrectly, allowing a local X client to read bytes beyond the GLX request buffer—information disclosure. An out-of-bounds write path also exists but requires byte-swapped clients, which is disabled by default on Red Hat builds. Any local user who can connect to the X server display can trigger the read path. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.",
    "acknowledgement": "Upstream acknowledges Anonymous (Trend Micro Zero Day Initiative) as the original reporter.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:26566",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36798",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49519",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "tigervnc-0:1.1.0-25.el6_10.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36083",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-35.el7_9",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46473",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26562",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26709",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-0:1.20.11-28.el8_10.2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:28923",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "tigervnc-0:1.15.0-10.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26590",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26610",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-34.el9_8.2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29844",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-7.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36086",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-21.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36633",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46377",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36087",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-0:1.20.11-29.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36632",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46456",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36085",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-34.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36634",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46392",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-11.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "moderate"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50262\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50262\nhttps://gitlab.freedesktop.org/xorg/xserver/-/commit/6d459e4daf715bea8abdafa8fb130be2f8a1d145\nhttps://lists.x.org/archives/xorg-announce/2026-June/003702.html\nhttps://redhat.atlassian.net/browse/PSIRTSUPT-16950"
    ],
    "name": "CVE-2026-50262",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-02T00:00:00Z",
    "bugzilla": {
      "description": "xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow()",
      "id": "2485388",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485388"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-416",
    "details": [
      "A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.",
      "A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure."
    ],
    "statement": "Red Hat rates this issue as Moderate impact. In xorg-x11-server and xorg-x11-server-Xwayland, a local X client can trigger a use-after-free read in CreateSaverWindow() by changing window attributes and forcing the screen saver, leaking server memory to the client. Any local user who can connect to the X server display can attempt exploitation. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.",
    "acknowledgement": "Upstream acknowledges Anonymous (Trend Micro Zero Day Initiative) as the original reporter.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:26566",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36798",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49519",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "tigervnc-0:1.1.0-25.el6_10.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36083",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-35.el7_9",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46473",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26562",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26709",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-0:1.20.11-28.el8_10.2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:28923",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "tigervnc-0:1.15.0-10.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26590",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26610",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-34.el9_8.2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29844",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-7.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36086",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-21.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36633",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46377",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36087",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-0:1.20.11-29.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36632",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46456",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36085",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-34.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36634",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46392",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-11.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "moderate"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50263\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50263\nhttps://gitlab.freedesktop.org/xorg/xserver/-/commit/ecc634f1b2f7aa473d3a267eada98c4918bf9e05\nhttps://lists.x.org/archives/xorg-announce/2026-June/003702.html\nhttps://redhat.atlassian.net/browse/PSIRTSUPT-16950"
    ],
    "name": "CVE-2026-50263",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-02T00:00:00Z",
    "bugzilla": {
      "description": "xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat",
      "id": "2485389",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485389"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.",
      "An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root."
    ],
    "statement": "Red Hat rates this issue as Important impact. In xorg-x11-server and xorg-x11-server-Xwayland, a local X client that requests multiple DRI2BufferBackLeft attachments together with DRI2BufferFrontLeft can trigger an out-of-bounds heap write in DRIGetBuffers/DRIGetBuffersWithFormat. Any local user with X display access can trigger this. It may crash the server or, where the X server runs with elevated privileges, could contribute to local privilege escalation. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.",
    "acknowledgement": "This issue was discovered by Peter Hutterer (Red Hat).",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-22T00:00:00Z",
        "advisory": "RHSA-2026:26566",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36798",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36083",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-35.el7_9",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46473",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "tigervnc-0:1.8.0-36.el7_9.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26562",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26709",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-0:1.20.11-28.el8_10.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:28923",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "tigervnc-0:1.15.0-10.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36792",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46382",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "tigervnc-0:1.11.0-8.el8_4.16"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36791",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38810",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46460",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "tigervnc-0:1.12.0-6.el8_6.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36768",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38502",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46385",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "tigervnc-0:1.12.0-15.el8_8.18"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26590",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26610",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-34.el9_8.2",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29844",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "tigervnc-0:1.15.0-7.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36086",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-21.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36633",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46377",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "tigervnc-0:1.12.0-14.el9_2.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36087",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-0:1.20.11-29.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36632",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46456",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "tigervnc-0:1.13.1-8.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36085",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-34.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36634",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46392",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "tigervnc-0:1.14.1-11.el9_6"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "tigervnc",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "important"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50264\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50264\nhttps://gitlab.freedesktop.org/xorg/xserver/-/commit/339c279514326134b0878fc23ce6e9520440ce7f\nhttps://lists.x.org/archives/xorg-announce/2026-June/003702.html\nhttps://redhat.atlassian.net/browse/PSIRTSUPT-16950"
    ],
    "name": "CVE-2026-50264",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-05T00:00:00Z",
    "bugzilla": {
      "description": "libinput: local privilege escalation via crafted uinput devices",
      "id": "2485390",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485390"
    },
    "cvss3": {
      "cvss3_base_score": "6.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-78",
    "details": [
      "In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution",
      "A flaw was found in libinput. A local attacker with access to /dev/uinput can inject arbitrary udev properties through the libinput-device-group helper. This injection can lead to root code execution, for example, by exploiting REMOVE_CMD properties that are executed when a device is removed. This vulnerability allows an attacker to gain elevated privileges on the system."
    ],
    "statement": "This CVE is rated Moderate since /dev/uinput permissions are restricted to root by default on Red Hat Enterprise Linux.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39296",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libinput-0:1.30.1-2.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43290",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libinput-0:1.26.1-5.el10_0.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Will not fix",
        "package_name": "libinput",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Will not fix",
        "package_name": "libinput",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "libinput",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50292\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50292\nhttps://gitlab.freedesktop.org/libinput/libinput/-/work_items/1296"
    ],
    "name": "CVE-2026-50292",
    "mitigation": {
      "value": "Restrict access to /dev/uinput to trusted users only. This is the default on virtually all distributions but some packages install udev rules that allow a logged-in user to create uinput devices. Examples for this on Fedora are steam-device, antimicrox, kdeconnectd.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-14T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50593\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50593"
    ],
    "name": "CVE-2026-50593",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-24T00:00:00Z",
    "bugzilla": {
      "description": "librenswan: IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload",
      "id": "2494147",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494147"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-347",
    "details": [
      "Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG payload of an IKEv1 packet was encoded using PKCS #1 RSA Encryption as per RFC 2313. A remote attacker can use a variation on the Bleichenbacher attack to forge the SIG payload when small public exponents are being used (e.g., e=3), which could lead to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the SIG payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of remote IKE peers are not affected.",
      "A flaw was found in Libreswan's implementation of IKEv1 authentication via raw RSA signatures. When processing an IKEv1 packet using PKCS #1 v1.5 RSA encryption, the RSA_authenticate_hash_signature_raw_rsa() function fails to properly validate the length of the authentication hash. A remote, unauthenticated attacker could exploit this vulnerability by sending a specially crafted IKEv1 packet containing a shorter-than-expected hash payload. This triggers an assertion failure within the Libreswan daemon, causing it to crash and restart, leading to a persistent Denial of Service (DoS) condition if malicious packets are continuously transmitted.\nAdditionally, if the target system relies on RSA keys with weak public exponents (e.g., e=3), a Bleichenbacher-style signature forgery attack may be feasible, potentially allowing the attacker to bypass authentication entirely."
    ],
    "statement": "Red Hat Product Security rates this as having an Moderate security impact, because this vulnerability directly affects the availability of Libreswan VPN gateways utilizing legacy IKEv1 tunnels. IKEv1 is not default in modern RHEL; modern profiles enforce IKEv2. Because the crash occurs during the unauthenticated phase of the IKE negotiation, any exposed Libreswan service (server or client) accepting standard IKEv1 connections via the default (authby=rsasig) option is vulnerable to the Denial of Service aspect of this flaw.   \nAdditionally, the risk of the authentication bypass vector is mitigated to low on Red Hat Enterprise Linux due to system-wide Crypto-Policies that strictly disallow the generation and use of keys with weak public exponents. This completely neutralizes the worst-case Authentication Bypass and Impersonation vectors for CVE-2026-50721, confining the threat strictly to a DoS process crash.",
    "affected_release": [
      {
        "product_name": "Fast Datapath for Red Hat Enterprise Linux 9",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46986",
        "cpe": "cpe:/o:redhat:enterprise_linux:9::fastdatapath",
        "package": "libreswan-0:5.3.2-1.el9fdp"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46398",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libreswan-0:5.3.2-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55449",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libreswan-0:5.2-1.el10_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46396",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libreswan-0:4.12-2.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46397",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libreswan-0:4.15-10.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57741",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libreswan-0:4.15-8.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libreswan",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "libreswan",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "libreswan",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50721\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50721\nhttps://libreswan.org/security/CVE-2026-50721/\nhttps://libreswan.org/security/CVE-2026-50721/CVE-2026-50721.txt\nhttps://lists.libreswan.org/archives/list/swan-announce@lists.libreswan.org/thread/7BZBYREBGXFPS4TSWOZX37WABRZVLK74/"
    ],
    "name": "CVE-2026-50721",
    "mitigation": {
      "value": "To mitigate this vulnerability, consider the following strategic workarounds if upgrading Libreswan immediately is not viable:\n- Migrate to IKEv2: Disable IKEv1 entirely and migrate all connections to IKEv2. The vulnerable code path is tied specifically to IKEv1’s rigid handling of PKCS#1 v1.5 RSA-SHA1.\n- Switch to Pre-Shared Keys (PSK): Additionally, if the configuration is for static tunnels, and not for a group of Remote Access VPN Clients, the authentication can be changed to use PSK via \"authby=secret\" after coordination with the remote peer.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-24T00:00:00Z",
    "bugzilla": {
      "description": "librenswan: IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload",
      "id": "2494148",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494148"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-347",
    "details": [
      "Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the AUTH payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of the remote IKE peer are not affected.",
      "A flaw was found in Libreswan's implementation of IKEv2 authentication when processing signatures utilizing the RSASSA-PKCS1-v1_5 scheme. The RSA_authenticate_hash_signature_pkcs1_1_5_rsa() function does not correctly validate the DER encoding of the ASN.1 digest. A remote, unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted IKEv2 AUTH payload with a shorter-than-expected hash value. This triggers an internal assertion failure, causing the Libreswan daemon to abort and restart, leading to a Denial of Service (DoS). \nFurthermore, if the Libreswan gateway accepts connections using weak public RSA exponents (such as e=3), an attacker could execute a Bleichenbacher-style signature forgery attack to achieve an authentication bypass."
    ],
    "statement": "Red Hat Product Security rates this as having an Moderate security impact. This Moderate severity rating reflects the deployment reality on modern enterprise platforms. The worst-case authentication bypass vector is effectively non-exploitable due to system-wide Crypto-Policies that strictly block the weak RSA exponents required for the attack. Furthermore, the resulting Denial of Service is limited to a controlled process abort via an internal assertion check. Because the Libreswan service is natively managed by systemd with automatic fault-recovery rules enabled by default, the daemon will instantly restart following a crash. Consequently, a sustained outage requires a continuous and high-volume malicious packet flood, significantly lowering the real-world operational risk.",
    "affected_release": [
      {
        "product_name": "Fast Datapath for Red Hat Enterprise Linux 9",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46986",
        "cpe": "cpe:/o:redhat:enterprise_linux:9::fastdatapath",
        "package": "libreswan-0:5.3.2-1.el9fdp"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46398",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libreswan-0:5.3.2-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55449",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libreswan-0:5.2-1.el10_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46396",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libreswan-0:4.12-2.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46397",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libreswan-0:4.15-10.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57741",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libreswan-0:4.15-8.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libreswan",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "libreswan",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "libreswan",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50722\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50722\nhttps://libreswan.org/security/CVE-2026-50722\nhttps://libreswan.org/security/CVE-2026-50722/\nhttps://libreswan.org/security/CVE-2026-50722/CVE-2026-50722.txt\nhttps://lists.libreswan.org/archives/list/swan-announce@lists.libreswan.org/thread/7BZBYREBGXFPS4TSWOZX37WABRZVLK74/"
    ],
    "name": "CVE-2026-50722",
    "mitigation": {
      "value": "If upgrading to Libreswan is not immediately feasible, this vulnerability can be mitigated by enforcing modern signature algorithms, which effectively prevents Libreswan from falling back to the vulnerable legacy parser logic.\nExplicitly configure your authby (or leftauth/rightauth) parameters in /etc/ipsec.conf to exclusively permit ECDSA and RSASSA-PSS: ```authby=ecdsa,rsa-sha2```\nNote: Applying this mitigation will drop compatibility with native Windows VPN clients that do not support RSASSA-PSS.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-08T00:00:00Z",
    "bugzilla": {
      "description": "sqlite: SQLite: Information disclosure via Session Extension changeset merge path",
      "id": "2498172",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498172"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-488",
    "details": [
      "An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path",
      "A flaw was found in SQLite. A local attacker can exploit this vulnerability by manipulating the Session Extension changeset concat/changegroup merge path. This allows the attacker to obtain sensitive information, leading to information disclosure."
    ],
    "statement": "This flaw affects the SQLite Session Extension, an optional compile-time feature (SQLITE_ENABLE_SESSION) that is not enabled in all Red Hat SQLite builds. A local attacker who can supply a malformed changeset blob to an application using sqlite3changeset_concat() or the changegroup merge API can cause a small amount of adjacent memory to be disclosed in the output changeset. Red Hat Enterprise Linux 8 and early Red Hat Enterprise Linux 9 z-streams do not compile the Session Extension into their sqlite builds and are not affected. Builds that do include the Session Extension have not yet received the upstream fix.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23423",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "sqlite-main-3.53.2-1.hum1",
        "impact": "moderate"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-50813\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50813\nhttps://gist.github.com/junius-sec/f8acb66bafb80134c8e1a1c8c7c9f4f4\nhttps://github.com/sqlite/sqlite/commit/c597ed79d1bd03f57198d10d1f431adda293cf2e\nhttps://sqlite.org/src/info/869a51ae84df"
    ],
    "name": "CVE-2026-50813",
    "mitigation": {
      "value": "Restrict processing of SQLite Session Extension changeset files to those from trusted, authenticated sources. Applications should validate or sanitize changeset blobs before passing them to sqlite3changeset_concat() or sqlite3changegroup_add(). No further mitigation is available until an update containing the upstream fix is released.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-30T05:30:32Z",
    "bugzilla": {
      "description": "libsoup: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment",
      "id": "2452932",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452932"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-319",
    "details": [
      "A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.",
      "A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation."
    ],
    "statement": "Moderate impact. This flaw in libsoup allows sensitive session cookies to be transmitted in cleartext within the initial HTTP CONNECT request when establishing HTTPS tunnels through a configured HTTP proxy. A network-positioned attacker or a malicious HTTP proxy could intercept these cookies, potentially leading to session hijacking or user impersonation. This affects Red Hat Enterprise Linux systems configured to use an HTTP proxy for HTTPS connections.",
    "acknowledgement": "Red Hat would like to thank Kona Arctic for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:15968",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "libsoup3-0:3.6.5-3.el10_1.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19143",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libsoup3-0:3.6.5-3.el10_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-05-14T00:00:00Z",
        "advisory": "RHSA-2026:17482",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libsoup3-0:3.6.5-3.el10_0.15"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-09T00:00:00Z",
        "advisory": "RHSA-2026:24722",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libsoup-0:2.62.2-12.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14087",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libsoup-0:2.62.3-14.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14087",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "libsoup-0:2.62.3-14.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22716",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libsoup-0:2.62.3-2.el8_4.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22716",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libsoup-0:2.62.3-2.el8_4.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24344",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libsoup-0:2.62.3-2.el8_6.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-08T00:00:00Z",
        "advisory": "RHSA-2026:24344",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libsoup-0:2.62.3-2.el8_6.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22710",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libsoup-0:2.62.3-3.el8_8.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-03T00:00:00Z",
        "advisory": "RHSA-2026:22710",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libsoup-0:2.62.3-3.el8_8.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:13978",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libsoup-0:2.72.0-12.el9_7.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19356",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libsoup-0:2.72.0-16.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-05-28T00:00:00Z",
        "advisory": "RHSA-2026:21686",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "libsoup-0:2.72.0-8.el9_0.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22316",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libsoup-0:2.72.0-8.el9_2.11"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22323",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "libsoup-0:2.72.0-8.el9_4.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22317",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libsoup-0:2.72.0-10.el9_6.7"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-5119\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5119\nhttps://gitlab.gnome.org/GNOME/libsoup/-/issues/502"
    ],
    "name": "CVE-2026-5119",
    "mitigation": {
      "value": "To mitigate this issue, ensure that all HTTP proxies used for HTTPS tunnels are trusted and operate within a secure network. Avoid configuring applications to use untrusted HTTP proxies. If feasible, configure applications to bypass proxies for sensitive connections or utilize a secure proxy solution that encrypts the entire communication channel. A service restart or application reload may be required for changes to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-30T07:44:15Z",
    "bugzilla": {
      "description": "libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing",
      "id": "2452945",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452945"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.",
      "A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system."
    ],
    "statement": "Important: An integer overflow flaw in `libarchive` on 32-bit systems can lead to a heap buffer overflow. This vulnerability occurs when processing a specially crafted ISO9660 image, allowing an attacker to potentially execute arbitrary code. Red Hat Enterprise Linux 64-bit systems are not affected by this flaw.",
    "acknowledgement": "Red Hat would like to thank Elhanan Haenel for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8517",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libarchive-0:3.1.2-14.el7_9.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8534",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "libarchive-0:3.3.3-7.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8521",
        "cpe": "cpe:/o:redhat:rhel_aus:8.2",
        "package": "libarchive-0:3.3.2-8.el8_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9592",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "libarchive-0:3.3.3-1.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9592",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "libarchive-0:3.3.3-1.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8908",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "libarchive-0:3.3.3-6.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8908",
        "cpe": "cpe:/o:redhat:rhel_tus:8.6",
        "package": "libarchive-0:3.3.3-6.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8908",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.6",
        "package": "libarchive-0:3.3.3-6.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9026",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "libarchive-0:3.3.3-5.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:9026",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "libarchive-0:3.3.3-5.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8510",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libarchive-0:3.5.3-9.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-16T00:00:00Z",
        "advisory": "RHSA-2026:8510",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "libarchive-0:3.5.3-9.el9_7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8867",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "libarchive-0:3.5.3-2.el9_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8864",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libarchive-0:3.5.3-5.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8873",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "libarchive-0:3.5.3-5.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8866",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libarchive-0:3.5.3-7.el9_6.1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.12",
        "release_date": "2026-05-08T00:00:00Z",
        "advisory": "RHSA-2026:12274",
        "cpe": "cpe:/a:redhat:openshift:4.12::el8",
        "package": "rhcos-412.86.202604281506-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:21690",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202605271328-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:15087",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202605060243-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-05-13T00:00:00Z",
        "advisory": "RHSA-2026:14773",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202605060220-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.16",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:10097",
        "cpe": "cpe:/a:redhat:openshift:4.16::el9",
        "package": "rhcos-416.94.202604211449-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.17",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:17596",
        "cpe": "cpe:/a:redhat:openshift:4.17::el9",
        "package": "rhcos-417.94.202605112123-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.18",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:12071",
        "cpe": "cpe:/a:redhat:openshift:4.18::el9",
        "package": "rhcos-418.94.202604240015-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:20040",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202605201155-0"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1777325677"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1777325711"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-controller-rhel8:7.13.5-4.1777325710"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1777325680"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1777325709"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1777325680"
      },
      {
        "product_name": "RHEL-8 based Middleware Containers",
        "release_date": "2026-05-05T00:00:00Z",
        "advisory": "RHSA-2026:13812",
        "cpe": "cpe:/a:redhat:rhosemc:1.0::el8",
        "package": "rhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1777325708"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19724",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1779223654"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19725",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1779223651"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16008",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1778244559"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16009",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1778244531"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16030",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1778274666"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-05-07T00:00:00Z",
        "advisory": "RHSA-2026:14937",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1778156756"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-20T00:00:00Z",
        "advisory": "RHSA-2026:8944",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libarchive-main-3.8.7-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-04-22T00:00:00Z",
        "advisory": "RHSA-2026:9832",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1776868961"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1776868774"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1776868744"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1776868772"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-23T00:00:00Z",
        "advisory": "RHSA-2026:10065",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1776868842"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1777459441"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1777454300"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11768",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1777459504"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Under investigation",
        "package_name": "libarchive",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-5121\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5121\nhttps://github.com/advisories/GHSA-2vwv-vqpv-v8vc\nhttps://github.com/libarchive/libarchive/pull/2934"
    ],
    "name": "CVE-2026-5121",
    "mitigation": {
      "value": "To mitigate this issue, avoid processing untrusted ISO9660 images with applications that utilize `libarchive`. Users should only extract or read content from ISO images obtained from trusted sources.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-03-31T00:00:00Z",
    "bugzilla": {
      "description": "gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image",
      "id": "2453291",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453291"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-122",
    "details": [
      "A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.",
      "A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions."
    ],
    "statement": "An Important heap-based buffer overflow flaw exists in the `gdk-pixbuf` library's JPEG image loader. This vulnerability can be triggered automatically without user interaction when processing a specially crafted JPEG image, such as during thumbnail generation. Successful exploitation leads to application crashes and denial-of-service conditions in applications utilizing `gdk-pixbuf` for image handling.",
    "acknowledgement": "Red Hat would like to thank Kağan Çapar for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10707",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.1",
        "package": "gdk-pixbuf2-0:2.42.12-4.el10_1.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19127",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gdk-pixbuf2-0:2.42.12-4.el10_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11325",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gdk-pixbuf2-0:2.42.12-4.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12114",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "gdk-pixbuf2-0:2.36.12-5.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10741",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gdk-pixbuf2-0:2.36.12-8.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10741",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "gdk-pixbuf2-0:2.36.12-8.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support",
        "release_date": "2026-04-29T00:00:00Z",
        "advisory": "RHSA-2026:11806",
        "cpe": "cpe:/a:redhat:rhel_aus:8.2",
        "package": "gdk-pixbuf2-0:2.36.12-7.el8_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12062",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gdk-pixbuf2-0:2.36.12-7.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12062",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gdk-pixbuf2-0:2.36.12-7.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12115",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gdk-pixbuf2-0:2.36.12-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12115",
        "cpe": "cpe:/a:redhat:rhel_tus:8.6",
        "package": "gdk-pixbuf2-0:2.36.12-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12115",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.6",
        "package": "gdk-pixbuf2-0:2.36.12-7.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12060",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gdk-pixbuf2-0:2.36.12-7.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12060",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gdk-pixbuf2-0:2.36.12-7.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10708",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gdk-pixbuf2-0:2.42.6-6.el9_7.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19210",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gdk-pixbuf2-0:2.42.6-6.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "release_date": "2026-04-30T00:00:00Z",
        "advisory": "RHSA-2026:12061",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.0",
        "package": "gdk-pixbuf2-0:2.42.6-3.el9_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11326",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gdk-pixbuf2-0:2.42.6-4.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11328",
        "cpe": "cpe:/a:redhat:rhel_eus:9.4",
        "package": "gdk-pixbuf2-0:2.42.6-5.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-04-28T00:00:00Z",
        "advisory": "RHSA-2026:11327",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gdk-pixbuf2-0:2.42.6-6.el9_6.1"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19724",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1779223654"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-05-20T00:00:00Z",
        "advisory": "RHSA-2026:19725",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1779223651"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.2",
        "release_date": "2026-06-10T00:00:00Z",
        "advisory": "RHSA-2026:25096",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.2::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1780681984"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16008",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/model-opt-cuda-rhel9:1778244559"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16009",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-rocm-rhel9:1778244531"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-11T00:00:00Z",
        "advisory": "RHSA-2026:16030",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-cuda-rhel9:1778274666"
      },
      {
        "product_name": "Red Hat AI Inference Server 3.3",
        "release_date": "2026-05-12T00:00:00Z",
        "advisory": "RHSA-2026:16174",
        "cpe": "cpe:/a:redhat:ai_inference_server:3.3::el9",
        "package": "rhaiis/vllm-spyre-rhel9:1778244546"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "glycin-loaders",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "loupe",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "papers",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "snapshot",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gdk-pixbuf2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "librsvg2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-5201\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5201\nhttps://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/304"
    ],
    "name": "CVE-2026-5201",
    "mitigation": {
      "value": "To reduce the risk of exploitation, avoid opening or processing untrusted JPEG image files. This operational control helps prevent the automatic triggering of the vulnerability, for example, during thumbnail generation, which could otherwise lead to application instability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-29T00:00:00Z",
    "bugzilla": {
      "description": "gnutls: gnutls: Information disclosure via heap overread in RSA key exchange",
      "id": "2467450",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467450"
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-126",
    "details": [
      "A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.",
      "A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure."
    ],
    "acknowledgement": "Red Hat would like to thank Joshua Rogers (AISLE Research Team) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20613",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "gnutls-0:3.8.10-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26409",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "gnutls-0:3.8.9-9.el10_0.19"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20611",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "gnutls-0:3.6.16-8.el8_10.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "gnutls-0:3.6.14-10.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33125",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libtasn1-0:4.13-3.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "gnutls-0:3.6.16-5.el8_6.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30849",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libtasn1-0:4.13-3.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "gnutls-0:3.6.16-7.el8_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:30850",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libtasn1-0:4.13-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-05-26T00:00:00Z",
        "advisory": "RHSA-2026:20612",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "gnutls-0:3.8.10-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:41921",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "gnutls-0:3.7.6-21.el9_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32962",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "gnutls-0:3.8.3-4.el9_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:30004",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "gnutls-0:3.8.3-6.el9_6.4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:40762",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202607151909-0"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:13274",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "gnutls-main-3.8.13-1.hum1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "gnutls",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-5260\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5260\nhttps://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-10"
    ],
    "name": "CVE-2026-5260",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-11T18:32:32Z",
    "bugzilla": {
      "description": "vim: Vim: Arbitrary code execution via Python omni-completion",
      "id": "2487981",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487981"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-94",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pythoncomplete.vim for builds with the +python interpreter) executes the import and from statements found in the current buffer through Python's import machinery. Because the buffer's working directory is on sys.path, opening a hostile .py file with a sibling Python package and invoking omni-completion runs that package's top-level code as the editing user. This issue has been patched in version 9.2.0561.",
      "A flaw was found in Vim, a widely used command-line text editor. This vulnerability allows a local attacker to execute arbitrary code on the system. By opening a specially crafted Python file and then triggering the omni-completion feature, the attacker can cause Vim to run malicious code from a sibling Python package. This could lead to a complete compromise of the user's system."
    ],
    "statement": "This is an Important vulnerability in Vim that allows a local attacker to achieve arbitrary code execution. The flaw occurs when a user opens a specially crafted Python file and invokes omni-completion, leading to the execution of malicious code from a co-located Python package. This risk is present in Red Hat Enterprise Linux and other products where Vim is deployed with Python omni-completion enabled, potentially compromising the editing user's system.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38509",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "vim-2:9.1.083-9.el10_2.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55431",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38510",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-27.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38510",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-27.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38511",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38511",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.10"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54769",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202608130832-0"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-52858\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-52858\nhttps://github.com/vim/vim/commit/4b850457e12e1a678dd209f2868154f7553cbf8d\nhttps://github.com/vim/vim/releases/tag/v9.2.0561\nhttps://github.com/vim/vim/security/advisories/GHSA-52mc-rq6p-rc7c"
    ],
    "name": "CVE-2026-52858",
    "mitigation": {
      "value": "Users can mitigate this vulnerability by disabling Python omni-completion in Vim if it is not essential for their workflow. This prevents the execution of untrusted Python code when opening hostile files. To disable this feature, ensure that the `omnifunc` option in your Vim configuration (e.g., `~/.vimrc`) is not set to `pythoncomplete#Complete` or `python3complete#Complete`. Alternatively, users should avoid invoking omni-completion (`Ctrl-X Ctrl-O`) on Python files from untrusted sources. Disabling Python omni-completion may affect Python development functionality within Vim.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-11T18:33:09Z",
    "bugzilla": {
      "description": "vim: Vim: Denial of Service via out-of-bounds write in terminal handling",
      "id": "2487989",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487989"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snapshot is taken. For each screen cell it walks the cell's chars[] array with no upper bound, stopping only when it encounters a NUL terminator. When a cell legitimately fills all VTERM_MAX_CHARS_PER_CELL (6) slots — a base character plus five combining marks — the bundled libvterm returns the array without a terminating NUL, so the loop reads past the fixed six-element array and appends the out-of-bounds values to a buffer reserved for only six characters. A program whose output is rendered inside a :terminal window can trigger this with a short byte sequence and no Vim scripting, leading to a crash. This issue has been patched in version 9.2.0565.",
      "A flaw was found in Vim, an open-source command-line text editor. This vulnerability allows a program displaying output in a Vim terminal window to trigger an out-of-bounds write by sending a specific byte sequence. This can lead to a crash of the Vim application, resulting in a Denial of Service (DoS) for the user."
    ],
    "statement": "This Moderate flaw in Vim allows a local attacker to cause a denial of service. By displaying specially crafted output within a Vim `:terminal` window, an attacker can trigger an out-of-bounds write, leading to the application crashing. This primarily impacts users who interact with untrusted content or execute untrusted programs within Vim's terminal emulator.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-52859\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-52859\nhttps://github.com/vim/vim/commit/63680c6d3d52477817b49cd1a66e7aabe8a7aa19\nhttps://github.com/vim/vim/releases/tag/v9.2.0565\nhttps://github.com/vim/vim/security/advisories/GHSA-47gw-8gc3-mgcm"
    ],
    "name": "CVE-2026-52859",
    "mitigation": {
      "value": "Users should exercise caution when opening untrusted files or executing untrusted programs within vim's `:terminal` window. Avoiding interaction with untrusted content in this context can prevent the exploitation of this vulnerability, which leads to a denial of service.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-11T18:33:45Z",
    "bugzilla": {
      "description": "vim: Vim: Arbitrary code execution through Python omni-completion.",
      "id": "2487987",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487987"
    },
    "cvss3": {
      "cvss3_base_score": "8.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-94",
    "details": [
      "Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. Python evaluates function default values, parameter annotations, and class base expressions at definition time, so a hostile buffer can execute attacker-controlled Python expressions during omni-completion. The existing g:pythoncomplete_allow_import mitigation (GHSA-52mc-rq6p-rc7c) does not cover this path, because the attacker-controlled code is not a harvested import/from statement. This issue has been patched in version 9.2.0597.",
      "A flaw was found in Vim, an open-source command-line text editor. The Python omni-completion feature executes reconstructed function and class definitions from the current buffer. A remote attacker can exploit this by crafting a hostile buffer, leading to the execution of attacker-controlled Python expressions during omni-completion. This vulnerability can result in arbitrary code execution."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-52860\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-52860\nhttps://github.com/vim/vim/commit/c8c63673bc4253212820626aeeb75999d9a539d2\nhttps://github.com/vim/vim/releases/tag/v9.2.0597\nhttps://github.com/vim/vim/security/advisories/GHSA-52mc-rq6p-rc7c\nhttps://github.com/vim/vim/security/advisories/GHSA-65p9-mwwx-7468"
    ],
    "name": "CVE-2026-52860",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-24T00:00:00Z",
    "bugzilla": {
      "description": "kernel: netfilter: xt_policy: fix strict mode inbound policy matching",
      "id": "2492112",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492112"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-551",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nnetfilter: xt_policy: fix strict mode inbound policy matching\nmatch_policy_in() walks sec_path entries from the last transform to the\nfirst one, but strict policy matching needs to consume info->pol[] in\nthe same forward order as the rule layout.\nDerive the strict-match policy position from the number of transforms\nalready consumed so that multi-element inbound rules are matched\nconsistently.",
      "A flaw was found in the Linux kernel's netfilter component, which is responsible for network packet filtering. This vulnerability, located in the `xt_policy` module, involves an error in how strict inbound network policies are matched. This could allow an attacker to bypass established security rules, potentially leading to unauthorized network access or unintended exposure of services. The flaw could compromise the effectiveness of network traffic control."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-52920\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-52920\nhttps://lore.kernel.org/linux-cve-announce/2026062430-CVE-2026-52920-22f8@gregkh/T"
    ],
    "name": "CVE-2026-52920",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-24T00:00:00Z",
    "bugzilla": {
      "description": "kernel: netfilter: nf_log: validate MAC header was set before dumping it",
      "id": "2492091",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492091"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nnetfilter: nf_log: validate MAC header was set before dumping it\nThe fallback path of dump_mac_header() guards the MAC header access\nonly with \"skb->mac_header != skb->network_header\", without checking\nskb_mac_header_was_set(). When the MAC header is unset, mac_header is\n0xffff, so the test passes and skb_mac_header(skb) returns\nskb->head + 0xffff, ~64 KiB past the buffer; the loop then reads\ndev->hard_header_len bytes out of bounds into the kernel log.\nThis is reachable via the netdev logger: nf_log_unknown_packet() calls\ndump_mac_header() unconditionally, and an skb sent through AF_PACKET\nwith PACKET_QDISC_BYPASS reaches the egress hook with mac_header still\nunset (__dev_queue_xmit(), which would reset it, is bypassed).\nAdd the skb_mac_header_was_set() check the ARPHRD_ETHER path already\nuses, and replace the open-coded MAC header length test with\nskb_mac_header_len(). Only skbs with an unset MAC header are affected;\nvalid ones are dumped as before.\nBUG: KASAN: slab-out-of-bounds in dump_mac_header (net/netfilter/nf_log_syslog.c:831)\nRead of size 1 at addr ffff88800ea49d3f by task exploit/148\nCall Trace:\nkasan_report (mm/kasan/report.c:595)\ndump_mac_header (net/netfilter/nf_log_syslog.c:831)\nnf_log_netdev_packet (net/netfilter/nf_log_syslog.c:938 net/netfilter/nf_log_syslog.c:963)\nnf_log_packet (net/netfilter/nf_log.c:260)\nnft_log_eval (net/netfilter/nft_log.c:60)\nnft_do_chain (net/netfilter/nf_tables_core.c:285)\nnft_do_chain_netdev (net/netfilter/nft_chain_filter.c:307)\nnf_hook_slow (net/netfilter/core.c:619)\nnf_hook_direct_egress (net/packet/af_packet.c:257)\npacket_xmit (net/packet/af_packet.c:280)\npacket_sendmsg (net/packet/af_packet.c:3114)\n__sys_sendto (net/socket.c:2265)",
      "A flaw was found in the Linux kernel's netfilter logging component. This vulnerability occurs because the system does not properly check if a network packet's Media Access Control (MAC) header is valid before attempting to log it. A local attacker could send a specially crafted network packet, leading to an out-of-bounds read. This could result in the disclosure of sensitive information from kernel memory or cause a system crash, leading to a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-52942\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-52942\nhttps://lore.kernel.org/linux-cve-announce/2026062435-CVE-2026-52942-2530@gregkh/T"
    ],
    "name": "CVE-2026-52942",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-24T00:00:00Z",
    "bugzilla": {
      "description": "kernel: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls",
      "id": "2492295",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492295"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-266",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nppp: require CAP_NET_ADMIN in target netns for unattached ioctls\n/dev/ppp open is currently authorized against file->f_cred->user_ns,\nwhile unattached administrative ioctls operate on current->nsproxy->net_ns.\nAs a result, a local unprivileged user can create a new user namespace\nwith CLONE_NEWUSER, gain CAP_NET_ADMIN only in that new user namespace,\nand still issue PPPIOCNEWUNIT, PPPIOCATTACH, or PPPIOCATTCHAN against\nan inherited network namespace.\nRequire CAP_NET_ADMIN in the user namespace that owns the target network\nnamespace before handling unattached PPP administrative ioctls.\nThis preserves normal pppd operation in the network namespace it is\nactually privileged in, while rejecting the userns-only inherited-netns\ncase.",
      "A flaw was found in the Linux kernel's Point-to-Point Protocol (PPP) subsystem. A local unprivileged user can exploit this vulnerability by creating a new user namespace and bypassing authorization checks for unattached administrative input/output controls (ioctls). This allows the user to perform unauthorized administrative operations on an inherited network namespace, potentially leading to privilege escalation."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53075\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53075\nhttps://lore.kernel.org/linux-cve-announce/2026062405-CVE-2026-53075-9f2a@gregkh/T"
    ],
    "name": "CVE-2026-53075",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-25T00:00:00Z",
    "bugzilla": {
      "description": "kernel: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued",
      "id": "2492704",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492704"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-476",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nlocking/rtmutex: Skip remove_waiter() when waiter is not enqueued\nsyzbot triggered the following splat in remove_waiter() via\nFUTEX_CMP_REQUEUE_PI:\nKASAN: null-ptr-deref in range [0x0000000000000a88-0x0000000000000a8f]\nclass_raw_spinlock_constructor\nremove_waiter+0x159/0x1200 kernel/locking/rtmutex.c:1561\nrt_mutex_start_proxy_lock+0x103/0x120\nfutex_requeue+0x10e4/0x20d0\n__x64_sys_futex+0x34f/0x4d0\ntask_blocks_on_rt_mutex() does not arm the waiter upon deadlock detection,\nleaving waiter->task nil, where 3bfdc63936dd (\"rtmutex: Use waiter::task instead\nof current in remove_waiter()\") made this fatal.\nFurthermore, rt_mutex_start_proxy_lock() should not be calling into remove_waiter()\nupon a successfully grabbing the rtmutex. 1a1fb985f2e2 (\"futex: Handle early deadlock\nreturn correctly\"), moved the remove_waiter() out of __rt_mutex_start_proxy_lock()\n(where 'ret' was only ever 0 or < 0) into the wrapper. Tighten this check to\naccount for try_to_take_rt_mutex().",
      "A flaw was found in the Linux kernel's `rtmutex` locking mechanism. A local attacker could trigger a null-pointer dereference by using the `FUTEX_CMP_REQUEUE_PI` operation. This vulnerability occurs because the `remove_waiter()` function is called when the waiter is not properly enqueued, leading to a system crash and a denial of service (DoS). This issue was detected by KASAN (Kernel Address Sanitizer)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53163\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53163\nhttps://lore.kernel.org/linux-cve-announce/2026062550-CVE-2026-53163-0eb8@gregkh/T"
    ],
    "name": "CVE-2026-53163",
    "csaw": false
  },
  {
    "public_date": "2026-06-25T00:00:00Z",
    "bugzilla": {
      "description": "kernel: RDMA/srp: bound SRP_RSP sense copy by the received length",
      "id": "2492806",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492806"
    },
    "cwe": "CWE-130",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nRDMA/srp: bound SRP_RSP sense copy by the received length\nsrp_process_rsp() copies sense data from rsp->data + resp_data_len,\nwhere resp_data_len is the full 32-bit value supplied by the SRP target\nand is never checked against the number of bytes actually received\n(wc->byte_len). The copy length is bounded to SCSI_SENSE_BUFFERSIZE, so\nat most 96 bytes are copied, but the source offset is not bounded.\nA malicious or compromised SRP target on the InfiniBand/RoCE fabric that\nthe initiator has logged into can return an SRP_RSP with\nSRP_RSP_FLAG_SNSVALID set and a large resp_data_len. The receive buffer\nis allocated at the target-chosen max_ti_iu_len, so the source of the\nsense copy lands past the bytes actually received; with resp_data_len\nnear 0xFFFFFFFF it is gigabytes past the buffer and the read faults.\nCopy the sense data only if it has not been truncated, that is, only if\nthe response header, the response data, and the sense region fit within\nthe bytes actually received; otherwise drop the sense and log. The\nin-tree iSER and NVMe-RDMA receive paths already bound their parse by\nwc->byte_len; this brings ib_srp into line with them.",
      "A flaw was found in the Linux kernel's Remote Direct Memory Access (RDMA) SCSI RDMA Protocol (SRP) component. A malicious or compromised SRP target on the InfiniBand/RoCE fabric can exploit this vulnerability by sending a specially crafted SRP response with an excessively large data length. This can lead to an out-of-bounds read when processing sense data, causing read faults and potentially a denial of service (DoS) on the system."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53186\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53186\nhttps://lore.kernel.org/linux-cve-announce/2026062556-CVE-2026-53186-5b7e@gregkh/T"
    ],
    "name": "CVE-2026-53186",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-25T00:00:00Z",
    "bugzilla": {
      "description": "kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing",
      "id": "2492771",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492771"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-130",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nsctp: validate cached peer INIT chunk length in COOKIE_ECHO processing\nWhen a listening SCTP server processes a COOKIE_ECHO chunk, the cached\npeer INIT chunk embedded after the cookie is parsed and its parameters\nare later walked by sctp_process_init() using sctp_walk_params().\nHowever, the chunk header length of this cached INIT chunk was not\nvalidated against the remaining buffer in the COOKIE_ECHO payload. If\nthe length field is inflated, the parameter walk can run beyond the\nactual received data, leading to out-of-bounds reads and potential\nmemory corruption during later parameter handling (e.g. STATE_COOKIE\nprocessing and kmemdup() copies).\nAdd a bounds check in sctp_unpack_cookie() to ensure the cached INIT\nchunk length does not exceed the available data in the COOKIE_ECHO\nbuffer before it is used.",
      "A flaw was found in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation. A remote attacker could exploit this by sending a specially crafted COOKIE_ECHO chunk to a listening SCTP server. The server's failure to properly validate the length of a cached peer INIT chunk within the COOKIE_ECHO payload could lead to out-of-bounds reads and memory corruption. This could result in a denial of service or potentially information disclosure."
    ],
    "statement": "SCTP COOKIE_ECHO processing failed to validate the cached peer INIT chunk length against the remaining cookie buffer, allowing a remote SCTP peer to make parameter parsing walk beyond received data and potentially trigger OOB reads or later memory corruption in SCTP parameter handling. This allows sctp_process_init() and sctp_walk_params() to walk beyond the actual received buffer and can lead to out-of-bounds reads during later parameter handling such as STATE_COOKIE processing and kmemdup() copies.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53246\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53246\nhttps://lore.kernel.org/linux-cve-announce/2026062512-CVE-2026-53246-e748@gregkh/T"
    ],
    "name": "CVE-2026-53246",
    "mitigation": {
      "value": "To mitigate this issue, prevent module sctp from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-01T12:00:00Z",
    "bugzilla": {
      "description": "kernel: Linux kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite",
      "id": "2485368",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485368"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nnetfilter: bridge: make ebt_snat ARP rewrite writable\nThe ebtables SNAT target keeps the Ethernet source address rewrite\nbehind skb_ensure_writable(skb, 0).  This is intentional: at the bridge\nebtables hooks the Ethernet header is addressed through\nskb_mac_header()/eth_hdr(), while skb->data points at the Ethernet\npayload.  Asking skb_ensure_writable() for ETH_HLEN bytes would check\nthe payload, not the Ethernet header, and would reintroduce the small\npacket regression fixed by commit 63137bc5882a.\nHowever, the optional ARP sender hardware address rewrite is different.\nIt writes through skb_store_bits() at an offset relative to skb->data:\nskb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)\nskb_header_pointer() only safely reads the ARP header; it does not make\nthe later sender hardware address range writable.  If that range is\nstill held in a nonlinear skb fragment backed by a splice-imported file\npage, skb_store_bits() maps the frag page and copies the new MAC address\ndirectly into it.\nEnsure the ARP SHA range is writable before reading the ARP header and\nbefore calling skb_store_bits().",
      "A flaw was found in the Linux kernel's netfilter bridge ebtables SNAT (Source Network Address Translation) module. This vulnerability allows a local attacker on a system configured with specific bridge netfilter rules to improperly modify underlying memory pages during an ARP (Address Resolution Protocol) sender hardware address rewrite. This could lead to unintended system behavior, a denial of service, or potentially local privilege escalation, where an attacker gains higher access rights than intended."
    ],
    "statement": "An Important flaw in the Linux kernel's ebtables SNAT target allows a local attacker to achieve privilege escalation, memory corruption, or denial of service. This vulnerability requires specific bridge netfilter rules to be configured, limiting its impact to systems with such specialized network configurations.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39082",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::nfv",
        "package": "kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39083",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "kernel-0:4.18.0-553.143.1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36645",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "kernel-0:5.14.0-687.23.1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36645",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "kernel-0:5.14.0-687.23.1.el9_8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux for NVIDIA 26",
        "fix_state": "Will not fix",
        "package_name": "kernel",
        "cpe": "cpe:/a:redhat:enterprise_linux_nvidia:"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53266\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53266\nhttps://lore.kernel.org/linux-cve-announce/2026062517-CVE-2026-53266-6162@gregkh/T/#u"
    ],
    "name": "CVE-2026-53266",
    "mitigation": {
      "value": "Disable ARP hardware address rewriting in ebtables SNAT rules, or remove ebtables SNAT rules that operate on ARP traffic on bridge interfaces.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-19T00:00:00Z",
    "bugzilla": {
      "description": "kernel: fuse: re-lock request before replacing page cache folio",
      "id": "2502255",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502255"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nfuse: re-lock request before replacing page cache folio\nfuse_try_move_folio() unlocks the request on entry but does not\nre-lock it on the success path. This means fuse_chan_abort() can end the\nrequest and free the fuse_io_args (eg fuse_readpages_end()) while the\nsubsequent copy chain logic after fuse_try_move_folio() accesses the\nfuse_io_args, leading to use-after-free issues.\nFix this by calling lock_request() before replace_page_cache_folio().\nThis ensures the request is locked on the success path which will\nprevent the fuse_io_args from being freed while the later copying logic\nruns, and also ensures that the ap->folios[i]->mapping is never null\nsince ap->folios[i] will always point to the newfolio after\nreplace_page_cache_folio().",
      "A flaw was found in the Linux kernel's Filesystem in Userspace (FUSE) component. The `fuse_try_move_folio()` function, responsible for managing page cache folios, fails to re-lock a request after initially unlocking it on a successful path. This oversight allows another function, `fuse_chan_abort()`, to prematurely free critical input/output arguments (`fuse_io_args`). Consequently, subsequent operations attempting to access these freed arguments can lead to a use-after-free vulnerability, potentially allowing an attacker to cause a system crash or execute arbitrary code."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "erlang27",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "important"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53388\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53388\nhttps://lore.kernel.org/linux-cve-announce/2026071935-CVE-2026-53388-eeaf@gregkh/T"
    ],
    "name": "CVE-2026-53388",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-19T00:00:00Z",
    "bugzilla": {
      "description": "kernel: NFSv4/flexfiles: reject zero filehandle version count",
      "id": "2502240",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502240"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-476",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nNFSv4/flexfiles: reject zero filehandle version count\nff_layout_alloc_lseg() decodes the filehandle-version array count\nfrom the flexfiles layout body. The value is used as the count for\nkzalloc_objs(), and the current code only rejects NULL.\nA zero count yields ZERO_SIZE_PTR, which can be stored in\ndss_info->fh_versions even though later flexfiles paths assume that at\nleast one filehandle version exists.\nReject fh_count == 0 before the allocation, matching the existing zero\nversion_count validation in the flexfiles GETDEVICEINFO parser.\nA QEMU/KASAN run with a malformed flexfiles layout hit:\nKASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\nRIP: 0010:ff_layout_encode_ff_layoutupdate.isra.0+0x15f/0x750\nff_layout_encode_layoutreturn+0x683/0x970\nnfs4_xdr_enc_layoutreturn+0x278/0x3a0\nKernel panic - not syncing: Fatal exception\nThe patched kernel rejects the malformed layout without KASAN/oops/panic,\nand a valid fh_count=1 regression still opens, reads, and unmounts cleanly.",
      "A flaw was found in the Linux kernel's NFSv4 (Network File System version 4) flexfiles component. This vulnerability occurs when the ff_layout_alloc_lseg() function processes a malformed flexfiles layout that specifies a zero filehandle version count. An attacker could exploit this by providing a specially crafted flexfiles layout, leading to a null-pointer dereference and ultimately causing a kernel panic, resulting in a Denial of Service (DoS) for the system."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53392\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53392\nhttps://lore.kernel.org/linux-cve-announce/2026071956-CVE-2026-53392-540c@gregkh/T"
    ],
    "name": "CVE-2026-53392",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-19T00:00:00Z",
    "bugzilla": {
      "description": "kernel: nfsd: release layout stid on setlease failure",
      "id": "2502239",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502239"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nnfsd: release layout stid on setlease failure\nnfs4_alloc_stid() publishes the new stid into cl->cl_stateids via\nidr_alloc_cyclic() under cl_lock before returning to\nnfsd4_alloc_layout_stateid(). When nfsd4_layout_setlease() then\nfails, the error path frees the layout stateid directly with\nkmem_cache_free() without ever calling idr_remove(), leaving the\nIDR slot pointing at freed slab memory. Any subsequent IDR walker\n(states_show, client teardown) dereferences the dangling pointer.\nThe correct teardown for an IDR-published stid is nfs4_put_stid(),\nwhich removes the IDR slot under cl_lock, dispatches sc_free\n(nfsd4_free_layout_stateid) to release ls->ls_file via\nnfsd4_close_layout(), and drops the nfs4_file reference in its\ntail.\nA second issue blocks that switch: nfsd4_free_layout_stateid()\nunconditionally inspects ls->ls_fence_work via\ndelayed_work_pending() under ls_lock, but\nINIT_DELAYED_WORK(&ls->ls_fence_work, ...) currently runs only\nafter the setlease call. On the setlease-failure path the\ndestructor would touch an uninitialized delayed_work.\nnfsd4_alloc_layout_stateid()\nnfs4_alloc_stid()           /* idr_alloc_cyclic under cl_lock */\nnfsd4_layout_setlease()     /* fails */\nnfs4_put_stid()\nnfsd4_free_layout_stateid()\ndelayed_work_pending(&ls->ls_fence_work)  /* needs INIT */\nnfsd4_close_layout()  /* nfsd_file_put(ls->ls_file) */\nput_nfs4_file()\nFix by hoisting the ls_fenced / ls_fence_delay / INIT_DELAYED_WORK\ninitialization above the nfsd4_layout_setlease() call, and replace\nthe manual nfsd_file_put + put_nfs4_file + kmem_cache_free cleanup\nwith a single nfs4_put_stid(stp).",
      "A flaw was found in the Linux kernel's Network File System Daemon (nfsd). When a `setlease` operation fails, the system prematurely releases a layout state identifier. An attacker could exploit this by triggering the failure, leading to a use-after-free vulnerability. This could result in a system crash, causing a Denial of Service (DoS)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "erlang27",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "important"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53399\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53399\nhttps://lore.kernel.org/linux-cve-announce/2026071958-CVE-2026-53399-c8aa@gregkh/T"
    ],
    "name": "CVE-2026-53399",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-29T20:39:45Z",
    "bugzilla": {
      "description": "Apache Tomcat: Apache Tomcat: Incorrect control flow in rewrite valve allows unexpected rule processing",
      "id": "2494681",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494681"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-358",
    "details": [
      "Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.",
      "A flaw was found in Apache Tomcat's rewrite valve. This vulnerability involves an incorrect control flow implementation where, during the processing of rewrite rules, if the first condition in an OR chain matched, subsequent non-OR conditions were unexpectedly skipped. This can lead to unintended rule processing, potentially allowing for security bypasses or unauthorized access due to misapplied configurations."
    ],
    "statement": "A flaw was found in Apache Tomcat's RewriteValve. When rewrite rules use OR-chained conditions followed by non-OR conditions, the processing logic may not evaluate conditions correctly, potentially allowing unintended rule matches. Exploitation requires the RewriteValve to be enabled with specific OR-chained condition patterns, which is not a default configuration.",
    "affected_release": [
      {
        "product_name": "Red Hat JBoss Web Server 6.2.4",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43402",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2",
        "package": "tomcat-catalina"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 10",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 8",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el9jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0.1",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49952",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
        "package": "tomcat-catalina"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 10",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49951",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
        "package": "jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 8",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49951",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
        "package": "jws7-tomcat-0:11.0.21-6.redhat_00005.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 9",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49951",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
        "package": "jws7-tomcat-0:11.0.21-6.redhat_00005.1.el9jws"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29203",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.56-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32960",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.23-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Fix deferred",
        "package_name": "jws5-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53404\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53404\nhttps://lists.apache.org/thread/rdhpghgfskrdmw9hqzjgjrtw538smpmz"
    ],
    "name": "CVE-2026-53404",
    "mitigation": {
      "value": "This vulnerability only affects Tomcat deployments that use the RewriteValve with OR-chained rewrite conditions. Deployments that do not use the RewriteValve are not affected. Review rewrite rules for OR-chained conditions and test rule evaluation behavior.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-02T14:30:14Z",
    "bugzilla": {
      "description": "LibRaw: LibRaw: Out-of-bounds read via `load_flags/raw_width` argument manipulation",
      "id": "2454372",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454372"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "A flaw has been found in LibRaw up to 0.22.0. This affects the function LibRaw::nikon_load_padded_packed_raw of the file src/decoders/decoders_libraw.cpp of the component TIFF/NEF. Executing a manipulation of the argument load_flags/raw_width can lead to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 0.22.1 mitigates this issue. This patch is called b8397cd45657b84e88bd1202528d1764265f185c. It is advisable to upgrade the affected component.",
      "A flaw was found in LibRaw. A remote attacker could exploit this vulnerability by manipulating the `load_flags` or `raw_width` arguments within the `LibRaw::nikon_load_padded_packed_raw` function. This manipulation can lead to an out-of-bounds read, potentially causing application instability or a denial of service."
    ],
    "statement": "Moderate impact. A flaw in LibRaw allows a remote attacker to trigger an out-of-bounds read by manipulating `load_flags` or `raw_width` arguments when processing specially crafted raw image files. This can lead to application instability or a denial of service. Red Hat products utilizing LibRaw to process untrusted raw image files are affected.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libraw1394",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "LibRaw",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-5342\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5342\nhttps://github.com/LibRaw/LibRaw/\nhttps://github.com/LibRaw/LibRaw/commit/b8397cd45657b84e88bd1202528d1764265f185c\nhttps://github.com/LibRaw/LibRaw/issues/795\nhttps://github.com/LibRaw/LibRaw/issues/795#issuecomment-4073769886\nhttps://github.com/biniamf/pocs/tree/main/libraw_nikonpadded\nhttps://vuldb.com/submit/781223\nhttps://vuldb.com/vuln/354671\nhttps://vuldb.com/vuln/354671/cti"
    ],
    "name": "CVE-2026-5342",
    "mitigation": {
      "value": "To mitigate this issue, avoid processing untrusted or maliciously crafted Nikon raw image files with applications that use LibRaw. This operational control prevents the exploitation of the out-of-bounds read vulnerability by limiting exposure to potentially harmful input.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-29T20:41:06Z",
    "bugzilla": {
      "description": "tomcat: Apache Tomcat: Error condition not handled when configuring CRLs",
      "id": "2494668",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494668"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-390",
    "details": [
      "Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.",
      "A flaw was found in Apache Tomcat. When configuring Certificate Revocation Lists (CRLs) for a FFM (presumably a specific type of connector), the system fails to detect and act upon an error condition. This oversight could lead to unexpected behavior or a security bypass, as the intended security controls might not be properly enforced."
    ],
    "statement": "A flaw was found in Apache Tomcat. When using the FFM-based connector with CRL-based certificate revocation checking, an error in CRL data processing is not handled correctly, potentially allowing revoked certificates to be accepted. This only affects Tomcat 10.1.0-M7+ and 11.x using the FFM connector (Java 22+ Foreign Function & Memory API) with CRL configuration — an extremely narrow set of conditions not present in standard Red Hat deployments.",
    "affected_release": [
      {
        "product_name": "Red Hat JBoss Web Server 7.0.1",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49952",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
        "package": "tomcat-coyote-ffm"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 10",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49951",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
        "package": "jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 8",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49951",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
        "package": "jws7-tomcat-0:11.0.21-6.redhat_00005.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 9",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49951",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
        "package": "jws7-tomcat-0:11.0.21-6.redhat_00005.1.el9jws"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29203",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.56-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32960",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.23-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Fix deferred",
        "package_name": "jws5-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Affected",
        "package_name": "tomcat-coyote-ffm",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53434\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53434\nhttps://lists.apache.org/thread/x510lbq0sfrd1qyo7q3r1mpllgpdcosk"
    ],
    "name": "CVE-2026-53434",
    "mitigation": {
      "value": "This vulnerability only affects Tomcat deployments using the FFM-based connector (requires Java 22+) with CRL-based certificate revocation checking. Deployments using the standard NIO/NIO2 connectors or not using CRL checking are not affected.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-10T22:02:22Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via missing memory request check",
      "id": "2487757",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487757"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.",
      "A flaw was found in ImageMagick. A remote attacker could exploit a missing check for maximum memory requests in the AcquireAlignedMemory function, leading to an out-of-memory condition. This vulnerability could result in a Denial of Service (DoS), making the affected system or application unavailable."
    ],
    "statement": "```\nIt is important to note that ImageMagick has been removed from Red Hat Enterprise Linux 8 and later releases. Therefore, current supported RHEL 8 and newer systems are not affected by this issue unless ImageMagick is installed from third-party or custom repositories.\nFor additional information, refer to https://access.redhat.com/solutions/4437561.\n```",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32961",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "ImageMagick-0:6.9.10.68-17.el7_9"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53460\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53460\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-q62c-h75r-2xhc"
    ],
    "name": "CVE-2026-53460",
    "mitigation": {
      "value": "Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-10T22:03:11Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via out-of-bounds heap write in ICON decoder",
      "id": "2487764",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487764"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.",
      "A flaw was found in ImageMagick. An incorrect loop in the ICON decoder can lead to an out-of-bounds heap write. This vulnerability allows a remote attacker to cause a denial of service (DoS) by providing a specially crafted image file, leading to a system crash."
    ],
    "statement": "```\nIt is important to note that ImageMagick has been removed from Red Hat Enterprise Linux 8 and later releases. Therefore, current supported RHEL 8 and newer systems are not affected by this issue unless ImageMagick is installed from third-party or custom repositories.\nFor additional information, refer to https://access.redhat.com/solutions/4437561.\n```",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53461\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53461\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g22q-f7gc-5jhr"
    ],
    "name": "CVE-2026-53461",
    "mitigation": {
      "value": "Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-10T22:04:53Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service due to heap-use-after-free in CheckPrimitiveExtent",
      "id": "2487761",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487761"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when an allocation fails in CheckPrimitiveExtent this can result in a heap-use-after-free and result in a crash. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.",
      "A flaw was found in ImageMagick. When an allocation fails in the `CheckPrimitiveExtent` function, it can lead to a heap-use-after-free vulnerability. This memory corruption issue can result in a denial of service (DoS) by causing the application to crash."
    ],
    "statement": "This flaw in ImageMagick is rated as Low impact. A heap-use-after-free vulnerability, triggered by a memory allocation failure during image processing, can lead to a denial of service. The high attack complexity required for exploitation reduces the overall risk to system availability in Red Hat environments.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53462\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53462\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-px7q-ggqj-hcf2"
    ],
    "name": "CVE-2026-53462",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-10T22:05:58Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via incorrect arguments in distort operation",
      "id": "2487746",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487746"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-476",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when passing incorrect arguments in the distort operation a null pointer deference will occur. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.",
      "A flaw was found in ImageMagick. When processing images, a remote attacker could provide incorrect arguments to the `distort` operation, leading to a null pointer dereference. This vulnerability can cause the application to crash, resulting in a Denial of Service (DoS) for affected systems."
    ],
    "statement": "This flaw in ImageMagick is rated as Moderate. A remote attacker could trigger a denial of service by providing specially crafted image arguments to the `distort` operation, leading to a null pointer dereference and application crash. Exploitation requires user interaction, limiting the immediate impact on Red Hat systems.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53463\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53463\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p9rq-q46c-g4x6"
    ],
    "name": "CVE-2026-53463",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-01T18:20:44Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via integer overflow in XCF decoder",
      "id": "2496131",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496131"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.",
      "A flaw was found in ImageMagick, a free and open-source software for editing and manipulating digital images. An attacker could craft a malicious image file that, when processed by the XCF decoder, triggers an integer overflow. This overflow leads to an out-of-bounds read, which can cause the application to crash, resulting in a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53466\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53466\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pjxj-pchx-4c3m"
    ],
    "name": "CVE-2026-53466",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-01T18:50:56Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Information disclosure vulnerability in MNG decoder",
      "id": "2496151",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496151"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-908",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG decoder contains a possible heap information disclosure vulnerability because part of the pixels are left unchanged. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.",
      "A flaw was found in ImageMagick. The MNG decoder in ImageMagick contains a heap information disclosure vulnerability. This flaw could allow an attacker to potentially access sensitive information from memory due to parts of image pixels being left unchanged during processing. This could lead to unauthorized disclosure of data."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53467\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53467\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8g53-9m3c-69xg"
    ],
    "name": "CVE-2026-53467",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-01T00:11:20Z",
    "bugzilla": {
      "description": "github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin",
      "id": "2495815",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2495815"
    },
    "cvss3": {
      "cvss3_base_score": "8.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-78",
    "details": [
      "containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.",
      "A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin, which manages container operations, fails to validate labels propagated from an image configuration to a container. This oversight could enable an attacker to execute arbitrary commands on the host system through a plugin that processes these unvalidated labels. The primary impact is host-root command execution, allowing unauthorized control over the underlying system."
    ],
    "statement": "A flaw was found in containerd where the CRI plugin propagates labels from an image configuration (LABEL instruction in a Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host via a plugin that consumes container labels for operations, such as the restart-monitor binary:// logger. An attacker who can cause a crafted container image to be pulled and run can achieve host-level code execution.",
    "affected_release": [
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37252",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/assisted-installer-agent-rhel9:1783592566"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.10",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37252",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.10::el9",
        "package": "multicluster-engine/assisted-service-9-rhel9:1783350355"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36105",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el8",
        "package": "multicluster-engine/assisted-installer-controller-rhel8:1783407939"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36105",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el8",
        "package": "multicluster-engine/assisted-installer-rhel8:1783407900"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36105",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el8",
        "package": "multicluster-engine/assisted-service-8-rhel8:1783332008"
      },
      {
        "product_name": "multicluster engine for Kubernetes 2.6",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36167",
        "cpe": "cpe:/a:redhat:multicluster_engine:2.6::el9",
        "package": "multicluster-engine/assisted-service-9-rhel9:1783333268"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42852",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784127491"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42852",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784562060"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42852",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-manager-rhel9:1784128029"
      },
      {
        "product_name": "Multicluster Global Hub 1.5.6",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42852",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1784127524"
      },
      {
        "product_name": "Multicluster Global Hub 1.7.0",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47149",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.7::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784768332"
      },
      {
        "product_name": "Multicluster Global Hub 1.7.0",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47149",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.7::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784906628"
      },
      {
        "product_name": "Multicluster Global Hub 1.7.0",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47149",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.7::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-manager-rhel9:1784768150"
      },
      {
        "product_name": "Multicluster Global Hub 1.7.0",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47149",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.7::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1784307548"
      },
      {
        "product_name": "Multicluster Global Hub 1.7.0",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53530",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.7::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1785775948"
      },
      {
        "product_name": "Multicluster Global Hub 1.7.0",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53530",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.7::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1785442872"
      },
      {
        "product_name": "Multicluster Global Hub 1.7.0",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53530",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.7::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-manager-rhel9:1785773056"
      },
      {
        "product_name": "Multicluster Global Hub 1.7.0",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53530",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.7::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1785773214"
      },
      {
        "product_name": "OpenShift API for Data Protection 1.3",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51033",
        "cpe": "cpe:/a:redhat:openshift_api_data_protection:1.3::el9",
        "package": "oadp/oadp-mustgather-rhel9:1785177359"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36873",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/submariner-rhel9-operator:1782933193"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47737",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/multicloud-integrations-rhel9:1784652040"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47737",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/multicluster-operators-channel-rhel9:1784741269"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47737",
        "cpe": "cpe:/a:redhat:acm:2.13::el9",
        "package": "rhacm2/multicluster-operators-subscription-rhel9:1784740143"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46903",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/multicluster-operators-channel-rhel9:1784707599"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46903",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/multicluster-operators-subscription-rhel9:1784229508"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47451",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/multicluster-operators-channel-rhel9:1784707599"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47451",
        "cpe": "cpe:/a:redhat:acm:2.15::el9",
        "package": "rhacm2/multicluster-operators-subscription-rhel9:1784229508"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.16",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57191",
        "cpe": "cpe:/a:redhat:acm:2.16::el9",
        "package": "rhacm2/multicluster-operators-channel-rhel9:1786908503"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.16",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57191",
        "cpe": "cpe:/a:redhat:acm:2.16::el9",
        "package": "rhacm2/multicluster-operators-subscription-rhel9:1786908777"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.10",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36625",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.10::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1783357140"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.11",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36207",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.11::el9",
        "package": "advanced-cluster-security/rhacs-main-rhel9:1783352589"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.11",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36207",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.11::el9",
        "package": "advanced-cluster-security/rhacs-operator-bundle:1783352589"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.11",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36207",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.11::el9",
        "package": "advanced-cluster-security/rhacs-rhel9-operator:1783352589"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.11",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36207",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.11::el9",
        "package": "advanced-cluster-security/rhacs-roxctl-rhel9:1783352589"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.11",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36207",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.11::el9",
        "package": "advanced-cluster-security/rhacs-scanner-v4-rhel9:1783352589"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.9",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36319",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-main-rhel8:1783357116"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security for Kubernetes 4.9",
        "release_date": "2026-07-30T00:00:00Z",
        "advisory": "RHSA-2026:48872",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
        "package": "advanced-cluster-security/rhacs-scanner-v4-rhel8:1785413210"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:35111",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "trivy-main-0.72.0-0.1.hum1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:41030",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784061472"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:41030",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784060681"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:41030",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-manager-rhel9:1784061010"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.4.2",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:41030",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1784060515"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44622",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784152046"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44622",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784561376"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44622",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-manager-rhel9:1784151884"
      },
      {
        "product_name": "Red Hat multicluster global hub 1.6.0",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44622",
        "cpe": "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
        "package": "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1784151772"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9:1786701839"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/cephcsi-rhel9-operator:1786701555"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-core-rhel9:1786702052"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/mcg-rhel9-operator:1786702559"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-console-rhel9:1786702713"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-client-rhel9-operator:1786702264"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1786702448"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/ocs-rhel9-operator:1786702276"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cli-rhel9:1786702440"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1786702315"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-console-rhel9:1786703071"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1786702563"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1786702636"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1786702623"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1786703137"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1786702716"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-must-gather-rhel9:1786702872"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odf-rhel9-operator:1786702949"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/odr-rhel9-operator:1786702917"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.19",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56366",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1786703143"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/cephcsi-rhel9:1786627460"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/cephcsi-rhel9-operator:1786626399"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/mcg-core-rhel9:1786628235"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/mcg-rhel9-operator:1786627106"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-client-console-rhel9:1786629761"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-client-rhel9-operator:1786627559"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-metrics-exporter-rhel9:1786687918"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/ocs-rhel9-operator:1786629478"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cli-rhel9:1786628142"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cloudnative-pg-rhel9-operator:1786631508"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-console-rhel9:1786628053"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-cosi-sidecar-rhel9:1786627382"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-csi-addons-rhel9-operator:1786627430"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-csi-addons-sidecar-rhel9:1786629076"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-external-snapshotter-rhel9-operator:1786627469"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-external-snapshotter-sidecar-rhel9:1786644072"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-multicluster-console-rhel9:1786688215"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-multicluster-rhel9-operator:1786628340"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-must-gather-rhel9:1786628623"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odf-rhel9-operator:1786632256"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/odr-rhel9-operator:1786628935"
      },
      {
        "product_name": "Red Hat Openshift Data Foundation 4.2",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57013",
        "cpe": "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
        "package": "odf4/rook-ceph-rhel9-operator:1786629548"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.4",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51084",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.4::el9",
        "package": "rhtas/policy-controller-rhel9-operator:1785942380"
      }
    ],
    "package_state": [
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "assisted/agent-preinstall-image-builder-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Assisted Installer for Red Hat OpenShift Container Platform 2",
        "fix_state": "Affected",
        "package_name": "rhai/assisted-installer-agent-rhel9",
        "cpe": "cpe:/a:redhat:assisted_installer:2"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "openshift-sandboxed-containers/osc-monitor-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "openshift-sandboxed-containers/osc-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Will not fix",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Deployment Validation Operator",
        "fix_state": "Affected",
        "package_name": "dvo/deployment-validation-rhel8-operator",
        "cpe": "cpe:/a:redhat:deployment_validator_operator"
      },
      {
        "product_name": "Gatekeeper 3",
        "fix_state": "Not affected",
        "package_name": "gatekeeper/gatekeeper-rhel9",
        "cpe": "cpe:/a:redhat:gatekeeper:3"
      },
      {
        "product_name": "Kernel Module Management Operator for Red Hat Openshift",
        "fix_state": "Affected",
        "package_name": "kmm/kernel-module-management-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:kernel_module_management:2"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Not affected",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:6"
      },
      {
        "product_name": "Logical Volume Manager Storage",
        "fix_state": "Not affected",
        "package_name": "lvms4/lvms-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:lvms:4"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/machine-deletion-remediation-operator-bundle",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "Machine Deletion Remediation Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/machine-deletion-remediation-rhel9-operator",
        "cpe": "cpe:/a:redhat:workload_availability_mdr:0"
      },
      {
        "product_name": "MCP Server for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-mcp-beta/openshift-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_mcp_server:0"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-log-reader-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Will not fix",
        "package_name": "migration-toolkit-virtualization/mtv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Will not fix",
        "package_name": "migration-toolkit-virtualization/mtv-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Will not fix",
        "package_name": "mtv-candidate/mtv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-agent-rhel8",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Affected",
        "package_name": "multicluster-engine/assisted-installer-controller-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Multicluster Engine for Kubernetes",
        "fix_state": "Not affected",
        "package_name": "multicluster-engine/must-gather-rhel9",
        "cpe": "cpe:/a:redhat:multicluster_engine"
      },
      {
        "product_name": "Node HealthCheck Operator",
        "fix_state": "Affected",
        "package_name": "workload-availability/node-healthcheck-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Out of support scope",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-agent-base-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel8",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Developer Tools and Services",
        "fix_state": "Affected",
        "package_name": "ocp-tools-4/jenkins-rhel9",
        "cpe": "cpe:/a:redhat:ocp_tools"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-agentic-sandbox-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/openshift-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-entrypoint-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-results-watcher-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Pipelines",
        "fix_state": "Affected",
        "package_name": "openshift-pipelines/pipelines-sidecarlogresults-rhel8",
        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
      },
      {
        "product_name": "OpenShift Serverless",
        "fix_state": "Affected",
        "package_name": "openshift-serverless-1/serverless-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:serverless:1"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 2",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-rhel8-operator",
        "cpe": "cpe:/a:redhat:service_mesh:2"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/istio-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Not affected",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:0"
      },
      {
        "product_name": "Power monitoring for Red Hat OpenShift",
        "fix_state": "Affected",
        "package_name": "openshift-power-monitoring/power-monitoring-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift_power_monitoring"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-grafana-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/acm-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Affected",
        "package_name": "rhacm2/multiclusterhub-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Not affected",
        "package_name": "rhacm2/submariner-operator-bundle",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Affected",
        "package_name": "advanced-cluster-security/rhacs-rhel8-operator",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Advanced Cluster Security 4",
        "fix_state": "Affected",
        "package_name": "advanced-cluster-security/rhacs-roxctl-rhel8",
        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/aap-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/aap-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/aap-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/aap-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Build of Kueue",
        "fix_state": "Not affected",
        "package_name": "kueue/kueue-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:kueue_operator:1"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-promtail-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 9",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/alloy-rhel10",
        "cpe": "cpe:/a:redhat:ceph_storage:9"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-spark-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Will not fix",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/rhai-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "kata-containers",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/cnf-tests-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/cnf-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/container-networking-plugins-microshift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4-dev-preview-beta/openperouter-edge-rhel10-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4-dev-preview-beta/openperouter-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4-dev-preview-beta/openperouter-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/kube-compare-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/lifecycle-agent-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/metallb-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/metallb-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/network-tools-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/network-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/numaresources-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/numaresources-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/numaresources-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/oc-mirror-plugin-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/oc-mirror-plugin-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-api-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-csr-approver-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-csr-approver-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-agent-installer-node-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-orchestrator-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-agent-installer-orchestrator-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ansible-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-azure-cluster-api-controllers-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-baremetal-installer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli-artifacts",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli-artifacts-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-ingress-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-kube-cluster-api-rhel8-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-cluster-olm-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-console",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-console-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-container-networking-plugins-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-container-networking-plugins-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-driver-shared-resource-mustgather-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-csi-driver-shared-resource-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-deployer",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-deployer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-builder",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-builder-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-docker-registry",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-helm-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-helm-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-installer-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-local-storage-mustgather-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-local-storage-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-machine-os-images-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-must-gather",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-node-feature-discovery",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-catalogd-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-catalogd-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-operator-controller-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-olm-operator-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-olm-rukpak-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ose-olm-rukpak-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-framework-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-lifecycle-manager",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-lifecycle-manager-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-operator-registry",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-registry-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-sdk-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-operator-sdk-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-ovn-kubernetes",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-sdn-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-secrets-store-csi-mustgather-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-secrets-store-csi-mustgather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tools-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ptp-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ptp-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Will not fix",
        "package_name": "openshift4/ztp-site-generate-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift-kni/commatrix",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/traefik-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift for Windows Containers",
        "fix_state": "Affected",
        "package_name": "openshift4-wincw/windows-machine-config-rhel9-operator",
        "cpe": "cpe:/a:redhat:windows_machine_config"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/argocd-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Will not fix",
        "package_name": "openshift-gitops-1/argocd-rhel9",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Affected",
        "package_name": "openshift-gitops-1/must-gather-rhel8",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift GitOps",
        "fix_state": "Affected",
        "package_name": "openshift-gitops-1/must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_gitops:1"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/cnv-must-gather-rhel8",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/cnv-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Will not fix",
        "package_name": "container-native-virtualization/multus-dynamic-networks-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/osp-director-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel9/osp-director-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/openstack-operator-bundle",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Not affected",
        "package_name": "rhoso-operators/rabbitmq-cluster-rhel9-operator",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Not affected",
        "package_name": "rhtpa/rhtpa-rhel9-operator",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53488\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53488\nhttps://github.com/containerd/containerd/security/advisories/GHSA-xhf5-7wjv-pqxp"
    ],
    "name": "CVE-2026-53488",
    "mitigation": {
      "value": "Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-14T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53689\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53689"
    ],
    "name": "CVE-2026-53689",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-10T00:00:00Z",
    "bugzilla": {
      "description": "gstreamer1-plugins-bad-free: GStreamer: Stack buffer overflow in H.265 buffering period SEI parser",
      "id": "2487612",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487612"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count cpb_cnt_minus1[0] from the referenced Sequence Parameter Set. A crafted H.265 video file or stream can cause the parser to write beyond the bounds of stack-allocated CPB delay arrays, resulting in a crash or potential stack memory corruption.",
      "A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count cpb_cnt_minus1[0] from the referenced Sequence Parameter Set. A crafted H.265 video file or stream can cause the parser to write beyond the bounds of stack-allocated CPB delay arrays, resulting in a crash or potential stack memory corruption."
    ],
    "statement": "The upstream maintainer confirmed this flaw causes crashes from crafted H.265 files or streams. Code execution is considered unlikely on Red Hat Enterprise Linux due to standard hardening measures including ASLR and stack protectors. The fix is public in GStreamer 1.28.3 (MR !11334, commit 48c11b7b01).",
    "acknowledgement": "Red Hat would like to thank Tianshuo Han for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "gstreamer1-plugins-bad-free",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "gstreamer1-plugins-bad-free",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "gstreamer1-plugins-bad-free",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "gstreamer1-plugins-bad-free",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53702\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53702"
    ],
    "name": "CVE-2026-53702",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-07-07T14:00:00Z",
    "bugzilla": {
      "description": "django: Django: Information disclosure via heap buffer over-read in GDALRaster",
      "id": "2497328",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497328"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-126",
    "details": [
      "An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.\n`django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Bence Nagy for reporting this issue.",
      "A flaw was found in Django. Instantiating django.contrib.gis.gdal.GDALRaster with a bytes object representing a raster file can trigger a heap buffer over-read in the vsi_buffer property, reading roughly 32 bytes past the end of the allocated buffer. An attacker who can supply crafted raster data may cause disclosure of adjacent heap memory or, in rare cases, crash the application process."
    ],
    "statement": "This vulnerability in Django is rated as Low impact. A heap buffer over-read in `django.contrib.gis.gdal.GDALRaster` can occur when processing specially crafted raster data provided as a bytes object. Exploitation is difficult due to the limited over-read size and specific input requirements, potentially leading to minor information disclosure or, rarely, a denial of service in Red Hat products that process untrusted geospatial raster data.",
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Self-service automation portal 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/bootc-automation-portal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_portal:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53877\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53877"
    ],
    "name": "CVE-2026-53877",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-07-22T13:42:50Z",
    "bugzilla": {
      "description": "diffutils: heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations",
      "id": "2506145",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506145"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds.\nWhen processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing. \nAn attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment.\nThis issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815 \nNOTE:\nThe project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges.",
      "A flaw was found in the diff3 program in the diffutils package. When processing specially crafted diff output, a heap-based buffer overflow can occur due to multiple signed integer overflows in line-mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds, resulting in a denial of service or memory corruption."
    ],
    "statement": "To exploit this vulnerability, an attacker needs to be able to control the output of the diff program used by diff3 (e.g., via --diff-program pointing to a malicious script) or convince a user to execute diff3 with specially crafted diff output. An attacker often needs prior execution privileges to supply the malicious diff output, meaning they already have the ability to execute arbitrary scripts on the system. Due to these reasons, this vulnerability has been rated with a low severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-24T00:00:00Z",
        "advisory": "RHSA-2026:45327",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "diffutils-main-3.12-6.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "diffutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "diffutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "diffutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "diffutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "diffutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53910\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53910\nhttps://cert.pl/en/posts/2026/07/CVE-2026-53910\nhttps://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50\nhttps://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815\nhttps://git.savannah.gnu.org/cgit/diffutils.git/"
    ],
    "name": "CVE-2026-53910",
    "mitigation": {
      "value": "To mitigate this vulnerability, do not run the diff3 program with untrusted input for the --diff-program argument or process untrusted diff output.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-03T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of 0 causes an unsigned subtraction elsewhere in the read path to underflow to approximately 4 GB. That oversized request reaches the core memory allocator, where the rounded size is computed in size_t but passed to new_block() as a 32-bit int; the low 32 bits of 0x100000000 are 0, so new_block() returns a small (~512-byte) block while the caller is told it received ~4 GB. The subsequent fill loop then streams attacker-controlled bytes past the end of the 544-byte allocation, producing an attacker-controlled heap buffer overflow. An authenticated user can crash the per-connection ProFTPD session child on demand with a single malformed SFTP packet (packet_len=0 followed by a body greater than approximately 544 bytes), producing reliable authenticated remote denial of service. Depending on heap layout and adjacent allocations, heap metadata corruption and further consequences beyond denial of service may be possible, though only denial of service is demonstrated by the supplied proof of concept."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-53994\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53994"
    ],
    "name": "CVE-2026-53994",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-54171\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-54171"
    ],
    "name": "CVE-2026-54171",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-28T11:58:54Z",
    "bugzilla": {
      "description": "glibc: glibc: Out-of-bounds write via TSIG record processing",
      "id": "2463465",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2463465"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
      "A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42694",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "glibc-0:2.39-128.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42733",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "glibc-0:2.28-251.el8_10.40"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42733",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "glibc-0:2.28-251.el8_10.40"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:42952",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glibc-0:2.34-274.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:42952",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glibc-0:2.34-274.el9_8"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46836",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1784821670"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46836",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1784821750"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-01T00:00:00Z",
        "advisory": "RHSA-2026:12740",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "glibc-main-2.42-12.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-gateway-opa-rhel9:1784775772"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-gateway-rhel9:1784775770"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-jaeger-query-rhel9:1784775834"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-operator-bundle:1784777166"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-query-rhel9:1784775793"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-rhel9:1784775768"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-rhel9-operator:1784775782"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50205",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/opentelemetry-collector-rhel9:1785704636"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50205",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/opentelemetry-rhel9-operator:1785704547"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1784794818"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1784794778"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1784795112"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1784794289"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1784795076"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "compat-glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "compat-glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-5435\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5435\nhttps://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u\nhttps://sourceware.org/bugzilla/show_bug.cgi?id=34033"
    ],
    "name": "CVE-2026-5435",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-29T13:00:00Z",
    "bugzilla": {
      "description": "acl: Symlink traversal privilege escalation via libacl functions",
      "id": "2490277",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490277"
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-59",
    "details": [
      "acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.",
      "A flaw was found in the `acl` package, specifically within its `libacl` pathname-based functions. A local attacker could exploit this vulnerability by using a symbolic link to replace a pathname component. This could allow the attacker to redirect access control list (ACL) read or write operations to arbitrary files or directories, leading to unauthorized manipulation of ACLs and ultimately local privilege escalation."
    ],
    "statement": "Red Hat rates this flaw as Important because a local attacker who controls any component of a pathname processed by a privileged process using libacl can redirect ACL operations to arbitrary files. Exploitation requires local access with the ability to create symlinks in a directory that a privileged program later processes with acl_get_file() or acl_set_file(). In default RHEL and OpenShift CoreOS configurations, standard file permission settings limit where unprivileged users can create symlinks, reducing the practical attack surface. Programs that operate on user-supplied paths with elevated privileges are most at risk.",
    "acknowledgement": "Red Hat would like to thank Alexander Peslyak <solar@openwall.com> and Andrew Tridgell <tridge60@gmail.com> for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42739",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "acl-0:2.4.0-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43420",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "acl-0:2.4.0-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42736",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "acl-0:2.4.0-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42736",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "acl-0:2.4.0-1.el9_8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54769",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202608130832-0"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46836",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1784821670"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46836",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1784821750"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34351",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "acl-main-2.4.0-0.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50205",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/opentelemetry-collector-rhel9:1785704636"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1784794818"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1784794778"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1784795112"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1784794289"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1784795076"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "acl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "acl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-54369\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-54369"
    ],
    "name": "CVE-2026-54369",
    "mitigation": {
      "value": "Restrict unprivileged users from creating symlinks in directories that privileged processes operate on with ACL commands. Where possible, use the fs.protected_symlinks sysctl (enabled by default on RHEL 7+), which prevents symlink following in world-writable sticky directories unless the owner of the symlink matches the owner of the target file or directory.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-29T13:00:00Z",
    "bugzilla": {
      "description": "acl: TOCTOU Symlink Traversal via getfacl/setfacl",
      "id": "2490279",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490279"
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-367",
    "details": [
      "acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.",
      "A time-of-check to time-of-use (TOCTOU) race condition vulnerability was found in `acl`. By replacing a pathname component with a symbolic link between a security check and subsequent file operations, an attacker can redirect file access control list operations. This occurs when privileged processes invoke `getfacl` or `setfacl` over an attacker-controlled path, potentially leading to local privilege escalation."
    ],
    "acknowledgement": "Red Hat would like to thank Alexander Peslyak <solar@openwall.com> and Andrew Tridgell <tridge60@gmail.com> for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42739",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "acl-0:2.4.0-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43420",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "acl-0:2.4.0-1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42736",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "acl-0:2.4.0-1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42736",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "acl-0:2.4.0-1.el9_8"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46836",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1784821750"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34351",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "acl-main-2.4.0-0.1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50205",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/opentelemetry-collector-rhel9:1785704636"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1784794818"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1784794778"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1784795112"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1784794289"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1784795076"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "acl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "acl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-54370\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-54370"
    ],
    "name": "CVE-2026-54370",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-29T13:00:00Z",
    "bugzilla": {
      "description": "attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr",
      "id": "2490283",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490283"
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-59",
    "details": [
      "attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.",
      "A flaw was found in the `attr` package. This vulnerability allows a local attacker to perform a symlink traversal attack by replacing a pathname component with a symbolic link - either during directory hierarchy traversal by `getfattr` or during backup restoration by `setfattr`, which reads and resolves full pathnames from backup files. In both cases, when these utilities are executed by a privileged process over a path controlled by the attacker, this can lead to local privilege escalation."
    ],
    "statement": "This Moderate severity flaw in the `getfattr` utility allows a local attacker to achieve privilege escalation. Exploitation requires a privileged process to invoke `getfattr` on a path controlled by the attacker, where a symbolic link can redirect operations to arbitrary files.",
    "acknowledgement": "Red Hat would like to thank Alexander Peslyak <solar@openwall.com> and Andrew Tridgell <tridge60@gmail.com> for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56133",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "attr-0:2.6.0-1.el8_10"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34889",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "attr-main-2.6.0-9.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "attr",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "attr",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "attr",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "attr",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-54371\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-54371"
    ],
    "name": "CVE-2026-54371",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-14T17:21:43Z",
    "bugzilla": {
      "description": "linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module",
      "id": "2488766",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488766"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-208",
    "details": [
      "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.",
      "A flaw was found in Linux-PAM's `pam_userdb` module. This vulnerability, categorized as an Observable Timing Discrepancy (CWE-208), allows a local or network-adjacent attacker to recover plaintext passwords. By repeatedly attempting authentication and measuring response-timing differences during plaintext password comparison, an attacker can deduce the password. This flaw is exploitable when the `pam_userdb` module is configured to store and compare credentials in plaintext, which is not a default setting."
    ],
    "statement": "This Moderate flaw in Linux-PAM's `pam_userdb` module allows a local or network-adjacent attacker to recover plaintext passwords through a timing discrepancy. This vulnerability requires the `pam_userdb` module to be explicitly configured to store and compare credentials in plaintext, which is not a default or recommended configuration in Red Hat Enterprise Linux environments. The impact is limited by the need for repeated authentication attempts and specific, non-default module configurations.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56131",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "pam-0:1.3.1-40.el8_10"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:35016",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "pam-main-1.7.2-2.2.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-10T00:00:00Z",
        "advisory": "RHSA-2026:7553",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "pam-main-1.7.2-1.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "pam",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "pam",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "pam",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "pam",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-54411\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-54411\nhttps://cwe.mitre.org/data/definitions/208.html\nhttps://github.com/linux-pam/linux-pam\nhttps://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h\nhttps://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"
    ],
    "name": "CVE-2026-54411",
    "mitigation": {
      "value": "To mitigate this issue, administrators should ensure that the `pam_userdb` module is not configured to store or compare credentials in plaintext. Verify that `pam_userdb` is either configured with a strong cryptographic hashing method or, if not required, is disabled. Avoid using `crypt=none` or omitting the `crypt=` argument when configuring `pam_userdb`. If changes are made to PAM configuration files, services relying on PAM may need to be restarted for the changes to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Critical",
    "public_date": "2026-08-03T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "9.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "status": ""
    },
    "cwe": "",
    "details": [
      "websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values 0x80 or above, a client can make the server parse these bytes into an ever-growing integer in lib/websocket/driver/draft75.js; because JavaScript numbers are 64-bit floating point values, this number will eventually lose precision and lead to the subsequent payload being parsed incorrectly. This issue is fixed in version 0.7.5."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-54466\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-54466"
    ],
    "name": "CVE-2026-54466",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-20T20:55:41Z",
    "bugzilla": {
      "description": "glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width",
      "id": "2459853",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459853"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
      "A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory."
    ],
    "statement": "Because this flaw requires that an affected application call the affected functions with an attacker-supplied value, Red Hat assesses the Attack Complexity of this flaw as High. Additionally, the flaw overflows a single byte onto the heap, so meaningful exploitation requires that the heap is structured such that a single byte can lead to an attacker-controlled outcome, or that the affected functions can be invoked with an attacker-controlled buffer base address. Regarding Attack Vector and Privileges Required, Red Hat assesses these elements as Local and Low respectively, as remote unauthenticated exploitation would require all the conditions above in a library client that listened on a network port and processed attacker-controllable data with the affected library functions.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33092",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "glibc-0:2.39-126.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33170",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "glibc-0:2.39-46.el10_0.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37395",
        "cpe": "cpe:/o:redhat:rhel_els:6",
        "package": "glibc-0:2.12-1.212.el6_10.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34211",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "glibc-0:2.17-326.el7_9.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37396",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "compat-glibc-1:2.12-4.el7_9.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33126",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "glibc-0:2.28-251.el8_10.38"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33126",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "glibc-0:2.28-251.el8_10.38"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36643",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "glibc-0:2.28-151.el8_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36643",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "glibc-0:2.28-151.el8_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33227",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "glibc-0:2.28-189.13.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33227",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "glibc-0:2.28-189.13.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33228",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "glibc-0:2.28-225.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33228",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "glibc-0:2.28-225.el8_8.17"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33226",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glibc-0:2.34-272.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33226",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glibc-0:2.34-272.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33231",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "glibc-0:2.34-60.el9_2.20"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33229",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "glibc-0:2.34-100.el9_4.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33230",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "glibc-0:2.34-168.el9_6.25"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.13",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:40021",
        "cpe": "cpe:/a:redhat:openshift:4.13::el9",
        "package": "rhcos-413.92.202607141229-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.14",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:43252",
        "cpe": "cpe:/a:redhat:openshift:4.14::el9",
        "package": "rhcos-414.92.202607210313-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.15",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:43226",
        "cpe": "cpe:/a:redhat:openshift:4.15::el9",
        "package": "rhcos-415.92.202607210244-0"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.19",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:40762",
        "cpe": "cpe:/a:redhat:openshift:4.19::el9",
        "package": "rhcos-4.19.9.6.202607151909-0"
      },
      {
        "product_name": "Cost Management Metrics Operator 4",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39981",
        "cpe": "cpe:/a:redhat:cost_management:4::el9",
        "package": "costmanagement/costmanagement-metrics-rhel9-operator:1783539156"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46836",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1784821670"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46836",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1784821750"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-01T00:00:00Z",
        "advisory": "RHSA-2026:12740",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "glibc-main-2.42-12.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34102",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1782890503"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50205",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/opentelemetry-collector-rhel9:1785704636"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50205",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/opentelemetry-rhel9-operator:1785704547"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1784794818"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1784794778"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1784795112"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1784794289"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1784795076"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "compat-glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-5450\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5450\nhttps://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997\nhttps://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450"
    ],
    "name": "CVE-2026-5450",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-25T17:16:18Z",
    "bugzilla": {
      "description": "jq: jq: Denial of Service via integer overflow and buffer overrun on 32-bit systems",
      "id": "2493030",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493030"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun.  This vulnerability is fixed in 1.8.2.",
      "A flaw was found in jq, a command-line JSON processor. On 32-bit systems, a local attacker could exploit an integer overflow vulnerability in the `jvp_string_append` function. This could lead to a massive buffer overrun, resulting in a denial of service (DoS) condition."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29986",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jq-main-1.8.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 4",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/a:redhat:ceph_storage:4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "jq",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-54679\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-54679\nhttps://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx"
    ],
    "name": "CVE-2026-54679",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-18T16:05:20Z",
    "bugzilla": {
      "description": "haproxy: HAProxy: Response smuggling due to integer overflow in FastCGI record length handling",
      "id": "2490522",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490522"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.",
      "A flaw was found in HAProxy. A malicious FastCGI (Fast Common Gateway Interface) backend can exploit an integer overflow vulnerability in the fcgi_conn structure's drl field. This occurs when specific contentLength and paddingLength values cause the drl field to wrap to zero, leading to incorrect record consumption. This desynchronizes the FCGI framing parser, potentially resulting in response smuggling, request routing errors, or memory safety issues."
    ],
    "statement": "Conditions for Exploitation: Successful exploitation requires a specific configuration where HAProxy is actively utilizing a FastCGI backend. Crucially, an attacker must already have control over this backend server to supply the maliciously crafted responses. \nThis requirement significantly restricts the attack vector, as it relies on an unlikely configuration or an already compromised backend, rather than a typical remote attack initiated by a client against a default frontend server.\nImpact Limitations: Although the vulnerability can cause the FastCGI framing parser to desynchronize—potentially leading to response smuggling, request routing errors, or memory safety issues—the threat is contained entirely to environments that process traffic from untrusted or compromised backend servers.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55679",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "haproxy-0:3.0.5-6.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55800",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "haproxy-0:3.0.5-4.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55772",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "haproxy-0:2.8.14-3.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55802",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "haproxy-0:2.4.17-6.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55801",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "haproxy-0:2.4.22-3.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55803",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "haproxy-0:2.4.22-4.el9_6.3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-03T00:00:00Z",
        "advisory": "RHSA-2026:35453",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "haproxy-main-3.0.25-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-haproxy-rhel8",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-haproxy-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-haproxy-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-haproxy-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 9",
        "fix_state": "Fix deferred",
        "package_name": "rhceph-ci/haproxy",
        "cpe": "cpe:/a:redhat:ceph_storage:9"
      },
      {
        "product_name": "Red Hat Ceph Storage 9",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-haproxy-rhel10",
        "cpe": "cpe:/a:redhat:ceph_storage:9"
      },
      {
        "product_name": "Red Hat Ceph Storage 9",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-haproxy-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "haproxy",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "haproxy",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "haproxy",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-haproxy-router",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-haproxy-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-cluster-api-controllers-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55203\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55203\nhttps://github.com/haproxy/haproxy/commit/5985276735777634d8c85f1d73bb7764aab0d6dd\nhttps://www.vulncheck.com/advisories/haproxy-integer-overflow-in-fcgi-demux-record-length-field"
    ],
    "name": "CVE-2026-55203",
    "mitigation": {
      "value": "To mitigate this issue, restrict access to HAProxy instances that utilize FastCGI to trusted FastCGI backends only. If FastCGI is not required, consider disabling its use in HAProxy configurations to eliminate the attack vector. Ensure that all FastCGI backends are secured and not susceptible to compromise. If the HAProxy service is reloaded or restarted after configuration changes, ensure proper validation of the new configuration.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-18T16:05:52Z",
    "bugzilla": {
      "description": "haproxy: HAProxy: Denial of Service via HPACK dynamic table insertions",
      "id": "2490518",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490518"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "HAProxy through  3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.",
      "A flaw was found in HAProxy. An attacker can trigger HPACK dynamic table insertions under memory pressure, leading to a null pointer dereference in the hpack_dht_insert() function. This can cause HAProxy worker processes to crash, resulting in a denial of service (DoS)."
    ],
    "statement": "This Important flaw in HAProxy can lead to a denial of service. An unauthenticated remote attacker could exploit a null pointer dereference by triggering HPACK dynamic table insertions under memory pressure, causing HAProxy worker processes to crash. This impacts the availability of services relying on HAProxy as a load balancer or proxy.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55679",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "haproxy-0:3.0.5-6.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55800",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "haproxy-0:3.0.5-4.el10_0.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55859",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "haproxy-0:1.8.27-5.el8_10.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55861",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "haproxy-0:1.8.27-2.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55861",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "haproxy-0:1.8.27-2.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55862",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "haproxy-0:1.8.27-4.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55862",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "haproxy-0:1.8.27-4.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55860",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "haproxy-0:1.8.27-5.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55860",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "haproxy-0:1.8.27-5.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55772",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "haproxy-0:2.8.14-3.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55802",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "haproxy-0:2.4.17-6.el9_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55801",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "haproxy-0:2.4.22-3.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55803",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "haproxy-0:2.4.22-4.el9_6.3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-03T00:00:00Z",
        "advisory": "RHSA-2026:35453",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "haproxy-main-3.0.25-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ceph Storage 5",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-haproxy-rhel8",
        "cpe": "cpe:/a:redhat:ceph_storage:5"
      },
      {
        "product_name": "Red Hat Ceph Storage 6",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-haproxy-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:6"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-haproxy-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-haproxy-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 9",
        "fix_state": "Fix deferred",
        "package_name": "rhceph-ci/haproxy",
        "cpe": "cpe:/a:redhat:ceph_storage:9"
      },
      {
        "product_name": "Red Hat Ceph Storage 9",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-haproxy-rhel10",
        "cpe": "cpe:/a:redhat:ceph_storage:9"
      },
      {
        "product_name": "Red Hat Ceph Storage 9",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-haproxy-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "haproxy",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "haproxy",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-haproxy-router",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-haproxy-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-hypershift-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-tests-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/ose-vsphere-cluster-api-controllers-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55204\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55204\nhttps://github.com/haproxy/haproxy/commit/9a6d1fe3f00d86ab4ea6ea6ea0a5d48fc058a513\nhttps://www.vulncheck.com/advisories/haproxy-null-pointer-dereference-in-hpack-dht-insert-function"
    ],
    "name": "CVE-2026-55204",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-29T20:42:23Z",
    "bugzilla": {
      "description": "tomcat: Apache Tomcat: Misleading security logs due to incorrect control flow",
      "id": "2494675",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494675"
    },
    "cvss3": {
      "cvss3_base_score": "2.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-778",
    "details": [
      "Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.",
      "A flaw was found in Apache Tomcat. Due to an always-incorrect control flow implementation, special roles and empty authorization constraints were not accurately included when the effective web.xml configuration was logged. This could lead to a security oversight where administrators might misinterpret the actual authorization constraints, potentially impacting the security posture of the application."
    ],
    "statement": "A flaw was found in Apache Tomcat. When the effective web.xml logging feature is enabled for debugging, special roles and empty authorization constraints may be omitted from the logged output. This is a logging-only issue with no runtime security impact — it only affects the accuracy of debug log output for administrators reviewing the effective web.xml configuration.",
    "affected_release": [
      {
        "product_name": "Red Hat JBoss Web Server 7.0.1",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49952",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
        "package": "tomcat-catalina"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 10",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49951",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
        "package": "jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 8",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49951",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
        "package": "jws7-tomcat-0:11.0.21-6.redhat_00005.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 9",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49951",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
        "package": "jws7-tomcat-0:11.0.21-6.redhat_00005.1.el9jws"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29203",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.56-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32960",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.23-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Fix deferred",
        "package_name": "jws5-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Affected",
        "package_name": "tomcat-catalina",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55276\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55276\nhttps://lists.apache.org/thread/jy09xjlzn6r2qwvqoph8vcmf959yq68v"
    ],
    "name": "CVE-2026-55276",
    "mitigation": {
      "value": "This is a logging-only issue with no runtime security impact. No mitigation is required. Administrators should not rely solely on the effective web.xml debug log output to verify security constraint configuration.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-18T18:00:12Z",
    "bugzilla": {
      "description": "nilfs-utils: NILFS utilities: Denial of Service via crafted NILFS2 images",
      "id": "2490544",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490544"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-1284",
    "details": [
      "NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.",
      "A flaw was found in NILFS utilities. An attacker can exploit this vulnerability by supplying a crafted NILFS2 image. This can lead to undefined behavior, oversized shifts, or out-of-memory conditions, ultimately causing a Denial of Service (DoS) by crashing tools such as nilfs-tune and dumpseg."
    ],
    "statement": "This Moderate impact flaw in NILFS utilities allows a local attacker to trigger a Denial of Service. By supplying a crafted NILFS2 image, an attacker can cause tools like `nilfs-tune` or `dumpseg` to crash due to improper validation of superblock fields. This requires user interaction with a malicious file.",
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55392\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55392\nhttps://github.com/nilfs-dev/nilfs-utils/commit/26efb5daff0757365101035145331b0a5a85d9d9\nhttps://github.com/nilfs-dev/nilfs-utils/issues/26"
    ],
    "name": "CVE-2026-55392",
    "mitigation": {
      "value": "To mitigate this issue, avoid processing NILFS2 images from untrusted sources. Restrict the use of NILFS utilities, such as `nilfs-tune` and `dumpseg`, to trusted administrators and environments. This reduces the exposure to specially crafted malicious NILFS2 images.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-29T00:00:00Z",
    "bugzilla": {
      "description": "curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse",
      "id": "2461204",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461204"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-488",
    "details": [
      "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
      "A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connection authenticated with different credentials, potentially leading to unauthorized access or information disclosure."
    ],
    "statement": "Moderate: A flaw in libcurl allows for the wrong reuse of HTTP Negotiate authenticated connections. This can occur when an application makes an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host, potentially leading to a request being sent over a connection authenticated with unintended credentials. This issue affects applications using libcurl versions from 7.10.6 up to and including 8.19.0.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:12916",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.20.0-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Fix deferred",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-5545\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5545\nhttps://curl.se/docs/CVE-2026-5545.html"
    ],
    "name": "CVE-2026-5545",
    "mitigation": {
      "value": "To mitigate this issue, applications using libcurl can disable connection reuse. This can be achieved by setting one of the following libcurl options: CURLOPT_FRESH_CONNECT to force a new connection for each request, CURLOPT_MAXCONNECTS to limit the total number of open connections, or CURLMOPT_MAX_HOST_CONNECTIONS when using the curl_multi API to limit connections per host. Disabling connection reuse may impact application performance due to increased overhead for establishing new connections.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-01T18:53:58Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via crafted 8BIM profile",
      "id": "2496157",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496157"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.",
      "A flaw was found in ImageMagick, a software suite for editing and manipulating digital images. An attacker could exploit a use-after-free vulnerability by providing a specially crafted image with an 8BIM profile containing a specific format string. This could lead to a denial of service, making the software unavailable."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55510\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55510\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-ff5c-8x9r-8qcw"
    ],
    "name": "CVE-2026-55510",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-01T18:56:28Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Heap buffer overflow in MVG decoder allows out-of-bounds write",
      "id": "2496142",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496142"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.",
      "A flaw was found in ImageMagick, free and open-source software for editing and manipulating digital images. A heap buffer overflow occurs in the MVG (Magick Vector Graphics) decoder when processing a specially crafted image. This vulnerability could allow an attacker to cause an out-of-bounds write, potentially leading to a denial of service or other impacts."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55577\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55577\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wx47-rm3x-jx6p"
    ],
    "name": "CVE-2026-55577",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-01T18:58:46Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via crafted image in MVG decoder",
      "id": "2496145",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496145"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.",
      "A flaw was found in ImageMagick, free and open-source software for editing and manipulating digital images. A missing depth check in the MVG (Magick Vector Graphics) decoder can lead to a stack overflow when a remote attacker provides a specially crafted image. This vulnerability could result in a Denial of Service (DoS), making the application unavailable."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55594\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55594\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mx48-2qq3-23hf"
    ],
    "name": "CVE-2026-55594",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-01T19:00:31Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via invalid arguments to connected-components option",
      "id": "2496147",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496147"
    },
    "cvss3": {
      "cvss3_base_score": "4.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-835",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.",
      "A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. This vulnerability allows an attacker to trigger an infinite loop by providing invalid arguments to the connected-components option. Successful exploitation of this flaw can lead to a Denial of Service (DoS), making the software unresponsive."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55595\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55595\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qhmf-7fc4-8q3h"
    ],
    "name": "CVE-2026-55595",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-01T18:16:23Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Unauthorized file access due to missing policy checks in concatenate operation",
      "id": "2496134",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496134"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-1220",
    "details": [
      "In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26.",
      "A flaw was found in ImageMagick. The `-concatenate` operation, used for combining images, lacks proper security policy checks. This oversight could allow an attacker to read from or write to file paths that should otherwise be restricted by the security policy. This could lead to unauthorized access to sensitive system resources."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55628\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55628\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-82mp-vp5c-9pf7"
    ],
    "name": "CVE-2026-55628",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-25T15:34:33Z",
    "bugzilla": {
      "description": "vim: Vim: Out-of-bounds Write in Spell File Word Count",
      "id": "2492980",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492980"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted .spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653.",
      "A flaw was found in Vim, an open-source command-line text editor. A remote attacker could exploit this vulnerability by tricking a user into loading a specially crafted spell file. When the user invokes spell suggestion, the editor attempts to process the malicious file, leading to an out-of-bounds write that corrupts memory and causes the application to crash, resulting in a denial of service."
    ],
    "statement": "This Moderate impact vulnerability in Vim's spell suggestion feature allows an attacker to cause a denial of service. By tricking a user into loading a specially crafted spell file and invoking spell suggestion, an out-of-bounds write can occur, leading to a crash of the editor. This requires user interaction and a malicious file, limiting its immediate exploitability.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48650",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "vim-2:9.1.083-9.el10_2.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55431",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48703",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-31.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48703",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-31.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47982",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47982",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.13"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54769",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202608130832-0"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-26T00:00:00Z",
        "advisory": "RHSA-2026:30267",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "vim-main-9.2.725-1.hum1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1786435241"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1786533457"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1786533449"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1786435483"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1786533529"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55693\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55693\nhttps://github.com/vim/vim/commit/a80874d9b84a01040e3d1aef2d4a59e1934dafb7\nhttps://github.com/vim/vim/releases/tag/v9.2.0653\nhttps://github.com/vim/vim/security/advisories/GHSA-wgh4-64f7-q3jq"
    ],
    "name": "CVE-2026-55693",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-07-22T13:09:30Z",
    "bugzilla": {
      "description": "unbound: Unbound: Information disclosure due to local policy bypass via unbound-control",
      "id": "2506131",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506131"
    },
    "cvss3": {
      "cvss3_base_score": "3.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-213",
    "details": [
      "In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.",
      "A flaw in Unbound's unbound-control utility can omit default-protected zones when initializing local data for a view. This allows queries for protected local names to bypass intended policies and leak to the public DNS, potentially exposing sensitive network information."
    ],
    "statement": "This is a Low impact flaw in Unbound. A highly privileged user, by using `unbound-control` to create a view without initial local data, can cause queries for internal network names to be sent to public DNS servers. This bypasses local policy and could lead to the disclosure of internal network information.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43588",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "unbound-main-1.25.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55708\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55708\nhttps://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55708.txt"
    ],
    "name": "CVE-2026-55708",
    "mitigation": {
      "value": "Do not run unbound-control view_local_data / view_local_datas on named views that started with no local-data; put local-data (or the RFC 1918 / AS112 / .onion / .localhost local-zones) in unbound.conf so the tree is built at startup with the defaults. If views or remote control are unused, leave control-enable: no and keep the control socket admin-only. Block Unbound from sending those names to the public Internet.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-22T13:09:40Z",
    "bugzilla": {
      "description": "unbound: Unbound: Denial of Service via crafted DNS responses with expired records",
      "id": "2506135",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506135"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain can crash the daemon. The serve-expired-client-timeout callback runs a two-pass loop to chase the respip-generated CNAME alias; on the second pass it resets 'alias_rrset' but not 'partial_rep'. Later, this inconsistency leads to a NULL pointer dereference and an eventual crash. A malicious actor can exploit the vulnerability by controlling any zone that replies with an A/AAAA record that falls inside the configured response-ip/rpz subnet. By delaying the answer when the previous record has expired, the vulnerable path of 'serve-expired-client-timeout' is taken leading to denial of service via the server crash.",
      "A flaw in Unbound allows a remote attacker controlling a delegated domain to trigger a NULL pointer dereference and crash the daemon. Exploitation occurs when serve-expired: yes and specific response-ip or RPZ rules are configured, resulting in a denial of service."
    ],
    "statement": "This Moderate severity denial of service flaw in Unbound requires specific configurations, including `serve-expired: yes` and either `response-ip` or RPZ CNAME override rules. Exploitation depends on a remote attacker controlling a delegated domain and delaying DNS responses, which limits the immediate impact on typical Red Hat Unbound deployments not utilizing these advanced features.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43588",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "unbound-main-1.25.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55717\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55717\nhttps://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55717.txt"
    ],
    "name": "CVE-2026-55717",
    "mitigation": {
      "value": "Ensure serve-expired remains disabled (default), or set serve-expired-client-timeout: 0 to bypass the vulnerable callback path. If serving expired answers is necessary, remove any response-ip CNAME redirect rules and RPZ rpz-cname-override entries. Additionally, use access-control to restrict query access, preventing untrusted clients from triggering the flaw via attacker-controlled names.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-25T15:32:41Z",
    "bugzilla": {
      "description": "vim: Vim: Denial of Service via crafted spell file",
      "id": "2492975",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492975"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.",
      "A flaw was found in Vim, an open-source command-line text editor. A remote attacker could exploit this vulnerability by convincing a user to load a specially crafted spell file. This malicious file can trigger a stack out-of-bounds write, which corrupts the editor's memory and causes it to crash. This leads to a Denial of Service (DoS), making the editor unavailable to the user."
    ],
    "statement": "A flaw was found in Vim's spell file handling. The dump_prefixes() function in src/spell.c does not validate the depth of the prefix trie against the size of fixed-size stack arrays, allowing a crafted .spl file to cause a stack out-of-bounds write and crash. Red Hat ships Vim in all RHEL versions and OpenShift CoreOS. Exploitation requires a user to load a malicious spell file and run :spelldump or spelling completion.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-03T00:00:00Z",
        "advisory": "RHSA-2026:35387",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "vim-main-9.2.780-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55892\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55892\nhttps://github.com/vim/vim/commit/8325b193bba5f01e7a7d8241f\nhttps://github.com/vim/vim/releases/tag/v9.2.0662\nhttps://github.com/vim/vim/security/advisories/GHSA-qm9w-fmpj-879h"
    ],
    "name": "CVE-2026-55892",
    "mitigation": {
      "value": "Do not load untrusted spell files (.spl) from unknown sources. Avoid using :spelldump with spell files of unknown provenance.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-25T15:31:29Z",
    "bugzilla": {
      "description": "vim: Vim: Arbitrary code execution via Vimscript code injection in netrw plugin",
      "id": "2492970",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492970"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-94",
    "details": [
      "Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and execute arbitrary Vimscript, including shell commands via :call system() and :!.  This vulnerability is fixed in 9.2.0663.",
      "A flaw was found in Vim, specifically within the netrw plugin. A local user could exploit a Vimscript code injection vulnerability by attempting to delete a specially crafted local file from the browser. This crafted filename, containing a bar character, could be interpolated into an Ex command, allowing for the execution of arbitrary Vimscript, including shell commands. This could lead to arbitrary code execution on the affected system."
    ],
    "statement": "This is an Important vulnerability in Vim's netrw plugin that could lead to arbitrary code execution. A local attacker could exploit this flaw by enticing a user to delete a specially crafted file within the netrw file browser, allowing for the injection and execution of arbitrary Vimscript commands, including shell commands. This risk is mitigated by the requirement for local user interaction and a specific sequence of actions.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55895\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55895\nhttps://github.com/vim/vim/commit/55bc757a5d436e59d50fe43f7cda94b118f86cb2\nhttps://github.com/vim/vim/releases/tag/v9.2.0663\nhttps://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjh"
    ],
    "name": "CVE-2026-55895",
    "mitigation": {
      "value": "To mitigate this vulnerability, users should avoid deleting untrusted or suspicious files directly from Vim's netrw file browser. Exercise caution when interacting with files from unknown or untrusted sources within the editor environment.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-29T20:44:39Z",
    "bugzilla": {
      "description": "tomcat: Apache Tomcat: Replay attack via improper authentication in EncryptionInterceptor",
      "id": "2494678",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494678"
    },
    "cvss3": {
      "cvss3_base_score": "4.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-294",
    "details": [
      "Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.\nUsers are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.",
      "A flaw was found in Apache Tomcat. An improper authentication vulnerability in the EncryptionInterceptor component allows a remote attacker to perform a replay attack. This could lead to unauthorized access or manipulation of data within the cluster component."
    ],
    "statement": "A flaw was found in Apache Tomcat's EncryptionInterceptor used for Tribes cluster communication. An improper authentication vulnerability allows a replay attack against encrypted cluster messages. Exploitation requires the EncryptionInterceptor to be configured for Tomcat clustering, which is a non-default configuration, and the attacker must have access to the cluster network to capture and replay messages. Apache rates this vulnerability as Low severity. Red Hat has corrected the impact from IMPORTANT to MODERATE — the original AI-Bot CVSS of 8.2 (AV:N/AC:L) incorrectly scored this as internet-facing with low complexity, when Tribes cluster traffic is adjacent-network (AV:A) and requires non-default clustering configuration (AC:H). The corrected vector is CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N (4.2).",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29203",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.56-1.hum1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32960",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.23-0.1.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Fix deferred",
        "package_name": "jws5-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Not affected",
        "package_name": "tomcat-catalina",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7",
        "fix_state": "Not affected",
        "package_name": "tomcat-catalina",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55955\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55955\nhttps://lists.apache.org/thread/g4p5sf45p3f9r011pwqs9r54yd64s106"
    ],
    "name": "CVE-2026-55955",
    "mitigation": {
      "value": "This vulnerability only affects Tomcat deployments using the EncryptionInterceptor for Tribes cluster communication. Deployments that do not use Tomcat clustering or do not configure the EncryptionInterceptor are not affected. Ensure cluster communication channels are restricted to trusted, isolated networks.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-29T20:46:02Z",
    "bugzilla": {
      "description": "tomcat: Apache Tomcat: Improper Authorization Allows Security Constraint Bypass",
      "id": "2494676",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494676"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-551",
    "details": [
      "Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.",
      "A flaw was found in Apache Tomcat where access control rules for the default servlet are improperly handled. An attacker can exploit this issue to bypass specific HTTP method restrictions, potentially gaining unauthorized access to protected application resources."
    ],
    "statement": "A security flaw in Apache Tomcat allows an attacker to bypass specific HTTP method restrictions on the default servlet. Red Hat products utilizing affected Tomcat versions are vulnerable if they rely on these method-specific security constraints. This could potentially enable unauthorized access to restricted application resources.",
    "affected_release": [
      {
        "product_name": "Red Hat JBoss Web Server 6.2.4",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43402",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2",
        "package": "tomcat-catalina"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 10",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 8",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6.2 on RHEL 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43401",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9",
        "package": "jws6-tomcat-0:10.1.49-15.redhat_00013.1.el9jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0.0",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39189",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
        "package": "tomcat-catalina"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 10",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 8",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 9",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39188",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
        "package": "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el9jws"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29203",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.56-1.hum1",
        "impact": "critical"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32960",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.23-0.1.hum1",
        "impact": "critical"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Out of support scope",
        "package_name": "jws5-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55956\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55956\nhttps://lists.apache.org/thread/dcjdcnnnww9hhdm016hr0l7hpw1bzjfp"
    ],
    "name": "CVE-2026-55956",
    "mitigation": {
      "value": "Review your application's web.xml file. Ensure security constraints explicitly deny unauthorized users by path, rather than relying strictly on filtering specific HTTP methods (like GET or POST).",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-29T20:47:12Z",
    "bugzilla": {
      "description": "tomcat: Apache Tomcat: Authentication bypass via missing critical step in JNDIRealm GSSAPI configuration",
      "id": "2494669",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494669"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-305",
    "details": [
      "Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.\nUsers are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.",
      "A flaw was found in Apache Tomcat. When the JNDIRealm was configured to authenticate binds using GSSAPI, an attacker could exploit a missing critical step in the authentication process. This allowed the attacker to bypass password verification and authenticate without providing the correct password, leading to unauthorized access."
    ],
    "statement": "This issue is rated as Important severity because it allows an attacker to fully bypass password verification when authenticating against a Tomcat instance, potentially gaining unauthorized access to protected resources without any privileges or user interaction required.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29203",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.56-1.hum1",
        "impact": "critical"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:32960",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.23-0.1.hum1",
        "impact": "critical"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Under investigation",
        "package_name": "jws5-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55957\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55957\nhttps://lists.apache.org/thread/7fk339o5jvd4mcgsf0chbrn4o525ccjh"
    ],
    "name": "CVE-2026-55957",
    "mitigation": {
      "value": "Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-22T13:10:01Z",
    "bugzilla": {
      "description": "unbound: NLnet Labs Unbound: Denial of Service via faulty DNSCrypt configuration",
      "id": "2506148",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506148"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').",
      "A flaw was found in Unbound when configured with DNSCrypt support. An unauthenticated remote attacker could exploit a faulty configuration, where an imbalance between DNSCrypt provider certificate and secret key files leads to memory corruption. By sending a specially crafted network request, the attacker can cause a garbage dereference, leading to a server crash and a denial of service (DoS)."
    ],
    "statement": "This Moderate flaw in Unbound can lead to a denial of service if the DNSCrypt feature is enabled and misconfigured. Exploitation requires Unbound to be compiled with DNSCrypt support, which is not a default setting in Red Hat products, and a specific mismatch between DNSCrypt provider certificate and secret key files. An unauthenticated attacker could then send a crafted UDP packet to trigger a server crash.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43588",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "unbound-main-1.25.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55990\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55990\nhttps://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55990.txt"
    ],
    "name": "CVE-2026-55990",
    "mitigation": {
      "value": "To mitigate this issue, ensure that Unbound is not compiled with DNSCrypt support if the feature is not required. If DNSCrypt support is enabled, verify that the number of 'dnscrypt-provider-cert:' files precisely matches the number of 'dnscrypt-secret-key:' files in the Unbound configuration to prevent the faulty configuration that leads to a denial of service. Restart the Unbound service after any configuration changes.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-08T00:00:00Z",
    "bugzilla": {
      "description": "xorg: X11: xserver: X.org: glamor Font Atlas Heap Buffer Overflow",
      "id": "2496165",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496165"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-805",
    "details": [
      "Local attackers with a X connection able to provide PCX fonts to the X \nserver xorg-server before 21.2.24 and xwayland before 24.1.13 could \ncause a heap buffer overflow via SetFont due to missing glyph boundary checks.",
      "A flaw was found in the glamor_font_get() function of the xorg-x11-server. This vulnerability, a heap buffer overflow, occurs when the server processes a specially crafted PCF font file where individual glyph metrics exceed the declared maximum bounds. An authenticated X client can exploit this by loading a malicious font and drawing text, potentially leading to arbitrary code execution with attacker-controlled content and extent. This affects servers utilizing the glamor acceleration backend, such as Xorg with the modesetting driver and Xwayland."
    ],
    "statement": "This Important flaw in xorg-x11-server allows an authenticated X client to achieve arbitrary code execution. By processing a malicious PCF font file where glyph metrics exceed declared bounds, a heap buffer overflow occurs within the glamor acceleration backend. This vulnerability primarily impacts Red Hat systems running Xorg with the modesetting driver or Xwayland, typically found in desktop environments.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38489",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50100",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "xorg-x11-server-Xwayland-0:24.1.5-6.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50117",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "xorg-x11-server-0:1.20.4-36.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38487",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-0:1.20.11-28.el8_10.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38488",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49606",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49606",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "xorg-x11-server-0:1.20.10-5.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49605",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53450",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49605",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-0:1.20.11-8.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53450",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50116",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52392",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50116",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-0:1.20.11-19.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52392",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-13.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38486",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-0:1.20.11-34.el9_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38490",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49515",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-0:1.20.11-21.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52397",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "xorg-x11-server-Xwayland-0:21.1.3-10.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49516",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-0:1.20.11-29.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52398",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "xorg-x11-server-Xwayland-0:22.1.9-8.el9_4.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49608",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-0:1.20.11-34.el9_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50718",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "xorg-x11-server-Xwayland-0:23.2.7-6.el9_6.3"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "xorg-x11-server",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-55999\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55999"
    ],
    "name": "CVE-2026-55999",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-08T00:00:00Z",
    "bugzilla": {
      "description": "libXfont2: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow",
      "id": "2496640",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496640"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "details": [
      "A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont",
      "A flaw was found in libXfont2. In the BitmapScaleBitmaps() function, an integer overflow can occur when calculating the memory needed for font glyphs. This overflow leads to a heap buffer overflow, where a smaller-than-required memory buffer is allocated. A local attacker can exploit this by loading a specially crafted PCF font, potentially leading to arbitrary code execution or a denial of service."
    ],
    "statement": "This flaw in libXfont2 is rated as Important. A local attacker could exploit an integer overflow in the `BitmapScaleBitmaps()` function, leading to a heap buffer overflow and potential arbitrary code execution or denial of service. This vulnerability requires the processing of a specially crafted PCF font, typically through an X server or an application configured to load untrusted font files.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47079",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libXfont2-0:2.0.6-5.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51061",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libXfont2-0:2.0.6-5.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51063",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libXfont2-0:2.0.3-2.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47103",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libXfont2-0:2.0.3-2.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51060",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libXfont2-0:2.0.3-2.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51060",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libXfont2-0:2.0.3-2.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51066",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libXfont2-0:2.0.3-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51066",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libXfont2-0:2.0.3-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51067",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libXfont2-0:2.0.3-2.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51067",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libXfont2-0:2.0.3-2.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:47084",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libXfont2-0:2.0.3-12.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51062",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libXfont2-0:2.0.3-12.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51058",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "libXfont2-0:2.0.3-12.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51059",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libXfont2-0:2.0.3-12.el9_6.1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56001\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56001"
    ],
    "name": "CVE-2026-56001",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-08T00:00:00Z",
    "bugzilla": {
      "description": "libXfont2: PCF Font Parsing Heap Buffer Overflow",
      "id": "2496641",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496641"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.",
      "A flaw was found in libXfont2. A specially crafted PCF (Portable Compiled Format) font file, when processed by libXfont2, can lead to a buffer overflow. This occurs because the font parsing process does not properly validate the size of a bitmap buffer against the glyph metrics provided in the malicious font file. An attacker could exploit this vulnerability by providing a malicious font, potentially leading to arbitrary code execution or a denial of service."
    ],
    "statement": "This is an Important flaw in libXfont2, affecting Red Hat Enterprise Linux. A heap buffer overflow during PCF font file parsing can lead to arbitrary code execution or denial of service. Exploitation requires processing a specially crafted font file, but does not necessitate rendering.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47079",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libXfont2-0:2.0.6-5.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51061",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libXfont2-0:2.0.6-5.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51063",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libXfont2-0:2.0.3-2.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47103",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libXfont2-0:2.0.3-2.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51060",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libXfont2-0:2.0.3-2.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51060",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libXfont2-0:2.0.3-2.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51066",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libXfont2-0:2.0.3-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51066",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libXfont2-0:2.0.3-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51067",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libXfont2-0:2.0.3-2.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51067",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libXfont2-0:2.0.3-2.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:47084",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libXfont2-0:2.0.3-12.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51062",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libXfont2-0:2.0.3-12.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51058",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "libXfont2-0:2.0.3-12.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51059",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libXfont2-0:2.0.3-12.el9_6.1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56002\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56002"
    ],
    "name": "CVE-2026-56002",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-08T00:00:00Z",
    "bugzilla": {
      "description": "libXfont2: computeProps Property Buffer Heap Buffer Overflow",
      "id": "2496642",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496642"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "details": [
      "A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51061",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libXfont2-0:2.0.6-5.el10_0.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51063",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "libXfont2-0:2.0.3-2.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47103",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libXfont2-0:2.0.3-2.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51060",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "libXfont2-0:2.0.3-2.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51060",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "libXfont2-0:2.0.3-2.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51066",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "libXfont2-0:2.0.3-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51066",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "libXfont2-0:2.0.3-2.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51067",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "libXfont2-0:2.0.3-2.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51067",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "libXfont2-0:2.0.3-2.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51062",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libXfont2-0:2.0.3-12.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51058",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "libXfont2-0:2.0.3-12.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51059",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "libXfont2-0:2.0.3-12.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "libXfont2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "libXfont2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56003\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56003"
    ],
    "name": "CVE-2026-56003",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-22T15:58:42Z",
    "bugzilla": {
      "description": "alsa-lib: ALSA library: Double-free vulnerability leading to memory corruption",
      "id": "2491439",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491439"
    },
    "cvss3": {
      "cvss3_base_score": "6.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.",
      "A flaw was found in the ALSA (Advanced Linux Sound Architecture) library. This double-free vulnerability, located in the `parse_def()` function, allows a local attacker to corrupt memory by providing specially crafted ALSA configuration text. When processing nested configuration blocks, the library attempts to free an already freed memory node. This can lead to system instability, crashes, or a denial of service (DoS)."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40573",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "alsa-lib-main-1.2.16.1-2.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "alsa-lib",
        "cpe": "cpe:/o:redhat:enterprise_linux:10",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "alsa-lib",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "alsa-lib",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "alsa-lib",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "alsa-lib",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "moderate"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56109\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56109\nhttps://github.com/alsa-project/alsa-lib/commit/536dd6f8affdf5197c12a63a71c92a70b2833cc0\nhttps://github.com/alsa-project/alsa-lib/releases/tag/v1.2.16.1\nhttps://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/\nhttps://www.vulncheck.com/advisories/alsa-library-double-free-via-parse-def-in-conf-c"
    ],
    "name": "CVE-2026-56109",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-19T02:56:36Z",
    "bugzilla": {
      "description": "libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking",
      "id": "2490668",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490668"
    },
    "cvss3": {
      "cvss3_base_score": "4.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-416",
    "details": [
      "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).",
      "A use-after-free vulnerability in libexpat occurs because handler call depth isn't properly tracked when XML_ResumeParser is invoked during policy violations. This flaw can lead to information disclosure, data corruption, or denial of service."
    ],
    "statement": "A Moderate impact use-after-free vulnerability exists in libexpat. This flaw, requiring local access and having high attack complexity, could lead to information disclosure, data corruption, or denial of service. The need for specific policy violations and local access substantially reduces the immediate risk in typical Red Hat environments.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:40486",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "expat-main-2.8.2-1.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "compat-expat1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "xmlrpc-c",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56131\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56131\nhttps://github.com/libexpat/libexpat/pull/1267"
    ],
    "name": "CVE-2026-56131",
    "mitigation": {
      "value": "To mitigate this vulnerability, avoid processing untrusted XML data in affected applications or ensure your implementation strictly validates and rejects malformed XML payloads before parsing.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-19T03:00:42Z",
    "bugzilla": {
      "description": "expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow",
      "id": "2490669",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490669"
    },
    "cvss3": {
      "cvss3_base_score": "6.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.",
      "A flaw was found in libexpat, a library used for parsing XML data. An attacker could exploit a heap-based buffer overflow, a type of memory error, by providing specially crafted XML input. This vulnerability occurs when the library mishandles memory reallocation while processing XML, particularly when multiple parsers share data. Successful exploitation could allow the attacker to execute arbitrary code, access sensitive information, or cause the application to crash, leading to a denial of service."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-28T00:00:00Z",
        "advisory": "RHSA-2026:30647",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "expat-main-2.8.2-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "compat-expat1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Under investigation",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "xmlrpc-c",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56132\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56132\nhttps://github.com/libexpat/libexpat/pull/1272"
    ],
    "name": "CVE-2026-56132",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Synopsis"
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56135\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56135"
    ],
    "name": "CVE-2026-56135",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "5.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "Synopsis"
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56136\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56136"
    ],
    "name": "CVE-2026-56136",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-19T00:00:00Z",
    "bugzilla": {
      "description": "libaom: libaom: arbitrary address write via SVC layer context OOB and cyclic refresh map pointer hijack",
      "id": "2490800",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490800"
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is fully deterministic and does not require a separate information leak. An attacker who can supply frames to a network-facing libaom encoder with SVC enabled could exploit this for denial of service or potential code execution.",
      "An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is fully deterministic and does not require a separate information leak. An attacker who can supply frames to a network-facing libaom encoder with SVC enabled could exploit this for denial of service or potential code execution."
    ],
    "statement": "This vulnerability is rated as Critical severity because it provides a fully deterministic arbitrary address write primitive that requires no information leak and is self-bootstrapping from attacker-controlled pixel values. The 1,200-byte write at an attacker-chosen address is sufficient for control flow hijacking. In Red Hat products, libaom ships bundled within Firefox and Thunderbird. The vulnerable code path requires the SVC (Scalable Video Coding) encoder feature to be enabled and the attacker to control both the layer_id configuration and the image frame pixel values. In Firefox's WebRTC implementation, SVC encoding parameters and frame submission are managed internally by the browser; a remote peer cannot directly set arbitrary layer IDs or inject pixel values into the local encoder. This significantly reduces exploitability in the browser context. RHEL-AI 3.4 (aom 3.12.0) and Hummingbird 1 (aom 3.13.3) ship standalone libaom packages within the affected version range. Services on those platforms that expose the SVC encoder API with attacker-controlled layer configuration and frame input are at highest risk.",
    "acknowledgement": "Red Hat would like to thank The FuzzAnything Team (FuzzAnything) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3 for RHEL 9",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51100",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "aom-0:3.14.0-1.el9ai"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.4 for RHEL 9",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51146",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
        "package": "aom-0:3.14.0-1.el9ai"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.5 for RHEL 9",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42875",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.5::el9",
        "package": "aom-0:3.14.0-1.el9ai"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-28T00:00:00Z",
        "advisory": "RHSA-2026:30814",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "aom-main-3.14.0-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cuda-12.9-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cuda-13.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-neuron-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-6.4-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-7.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-7.1-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-spyre-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-tpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-automl-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-autorag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-autogluon-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-llm-d-kv-cache-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mlserver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-spark-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56209\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56209\nhttps://aomedia.googlesource.com/aom/+/a93ba0ffaa\nhttps://issues.chromium.org/issues/503993984"
    ],
    "name": "CVE-2026-56209",
    "mitigation": {
      "value": "There is no complete mitigation for this vulnerability. The following measures can reduce risk:\n1. If using libaom as a standalone encoder library with SVC enabled, validate that spatial_layer_id and temporal_layer_id values are within the configured range [0, configured_layers) before calling aom_codec_control with AV1E_SET_SVC_LAYER_ID.\n2. Restrict access to encoding services to trusted clients only. Do not expose libaom SVC encoder configuration to untrusted input.\n3. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later).\n4. Deploy encoding services with ASLR, stack canaries, and other exploit mitigation technologies enabled.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-19T00:00:00Z",
    "bugzilla": {
      "description": "libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id",
      "id": "2490801",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490801"
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).",
      "A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory)."
    ],
    "statement": "This vulnerability is rated as Important severity because the 40KB out-of-bounds heap read can disclose sensitive information from adjacent heap allocations (including pointers useful for ASLR bypass in chained attacks) and reliably causes denial of service by hitting unmapped pages. In Red Hat products, libaom ships bundled within Firefox and Thunderbird. The vulnerable code path requires the SVC encoder feature to be enabled and an attacker to set spatial_layer_id to a value exceeding the number of configured spatial layers. In Firefox's WebRTC implementation, SVC layer parameters are managed internally by the browser and not directly exposed to remote peers, which limits exploitability. RHEL-AI 3.4 (aom 3.12.0) and Hummingbird 1 (aom 3.13.3) ship standalone libaom packages within the affected version range. Services that expose SVC encoder layer configuration to untrusted input are affected.",
    "acknowledgement": "Red Hat would like to thank The FuzzAnything Team (FuzzAnything) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3 for RHEL 9",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51100",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "aom-0:3.14.0-1.el9ai"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.4 for RHEL 9",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51146",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
        "package": "aom-0:3.14.0-1.el9ai"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.5 for RHEL 9",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42875",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.5::el9",
        "package": "aom-0:3.14.0-1.el9ai"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-28T00:00:00Z",
        "advisory": "RHSA-2026:30814",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "aom-main-3.14.0-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cuda-12.9-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cuda-13.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-neuron-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-6.4-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-7.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-7.1-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-spyre-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-tpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-automl-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-autorag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-autogluon-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-llm-d-kv-cache-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mlserver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-spark-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56210\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56210\nhttps://aomedia.googlesource.com/aom/+/a93ba0ffaa\nhttps://issues.chromium.org/issues/503975732"
    ],
    "name": "CVE-2026-56210",
    "mitigation": {
      "value": "There is no complete mitigation for this vulnerability. The following measures can reduce risk:\n1. If using libaom as a standalone encoder library with SVC enabled, validate that spatial_layer_id does not exceed the number of configured spatial layers before calling aom_codec_control with AV1E_SET_SVC_LAYER_ID.\n2. Restrict access to encoding services to trusted clients only.\n3. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later).\n4. Monitor encoding service processes for unexpected crashes (segfaults) that may indicate exploitation attempts.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-19T00:00:00Z",
    "bugzilla": {
      "description": "libaom: libaom: remote code execution via SVC layer context handling with attacker-controlled frames",
      "id": "2490802",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490802"
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic refresh map pointer, brute-force the process base address via a crash oracle, and redirect control flow to achieve arbitrary command execution. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames.",
      "A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic refresh map pointer, brute-force the process base address via a crash oracle, and redirect control flow to achieve arbitrary command execution. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames."
    ],
    "statement": "This vulnerability is rated as Critical severity because the researcher demonstrated successful remote code execution against a fork-based video processing service. The exploit chain leverages attacker-controlled pixel values to hijack internal encoder pointers, uses a crash oracle to brute-force ASLR, and ultimately achieves arbitrary command execution. However, the attack complexity is elevated: it requires a fork-based service architecture (for the crash oracle), multiple encoding attempts (for ASLR brute-force), and knowledge of the target binary layout. In Red Hat products, libaom ships bundled within Firefox and Thunderbird. Firefox does not use a fork-based architecture for WebRTC encoding, and SVC layer parameters are managed internally, making the demonstrated exploit chain not directly applicable to the browser context. RHEL-AI 3.4 (aom 3.12.0) and Hummingbird 1 (aom 3.13.3) ship standalone libaom packages within the affected version range. Fork-based transcoding or video conferencing services that use libaom with SVC encoding and accept attacker-supplied frames are at highest risk for this specific exploit chain.",
    "acknowledgement": "Red Hat would like to thank The FuzzAnything Team (FuzzAnything) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux AI 3.3 for RHEL 9",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51100",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
        "package": "aom-0:3.14.0-1.el9ai"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.4 for RHEL 9",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51146",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
        "package": "aom-0:3.14.0-1.el9ai"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI 3.5 for RHEL 9",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42875",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3.5::el9",
        "package": "aom-0:3.14.0-1.el9ai"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-28T00:00:00Z",
        "advisory": "RHSA-2026:30814",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "aom-main-3.14.0-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cuda-12.9-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-cuda-13.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-neuron-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-6.4-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-7.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-7.1-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-spyre-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-tpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-automl-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-autorag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-autogluon-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-llm-d-kv-cache-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mlserver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-spark-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56211\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56211\nhttps://aomedia.googlesource.com/aom/+/a93ba0ffaa\nhttps://issues.chromium.org/issues/503993985"
    ],
    "name": "CVE-2026-56211",
    "mitigation": {
      "value": "There is no complete mitigation for this vulnerability. The following measures can reduce risk:\n1. If using libaom as a standalone encoder in a fork-based service, validate all SVC layer parameters (spatial_layer_id, temporal_layer_id) against configured bounds before passing them to the encoder API.\n2. Avoid fork-based architectures for encoding services that accept untrusted input. Use thread-based or container-isolated workers instead, which prevent crash oracle attacks.\n3. Restrict access to encoding services to trusted clients only. Do not expose SVC encoder configuration or frame submission to untrusted network input.\n4. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later).\n5. Enable all available exploit mitigations (ASLR, PIE, stack canaries, CFI) on encoding service binaries.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-09T09:29:07Z",
    "bugzilla": {
      "description": "patch: GNU patch: Denial of Service via specially crafted patch file",
      "id": "2498468",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498468"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing.\nAn attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service.\nThis issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313",
      "A flaw was found in GNU patch. An attacker can exploit this by providing a specially crafted patch file, which leads to a NULL pointer dereference. This improper handling of end-of-file markers can corrupt internal data structures, causing the utility to crash. This results in a denial of service (DoS) for the affected system."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-10T00:00:00Z",
        "advisory": "RHSA-2026:38019",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "patch-main-2.8-4.3.hum1",
        "impact": "moderate"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56288\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56288\nhttps://cert.pl/en/posts/2026/07/CVE-2026-56288\nhttps://cgit.git.savannah.gnu.org/cgit/patch.git/\nhttps://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=e6d6a4e021660679d7fc9150f981d4920f722313"
    ],
    "name": "CVE-2026-56288",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-09T09:29:22Z",
    "bugzilla": {
      "description": "patch: GNU patch: Denial of Service via crafted unified-diff input",
      "id": "2498462",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498462"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-835",
    "details": [
      "GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position.\nThis results in excessive CPU consumption and prevents the process from completing.\nAn attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination.\nThis issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9",
      "A flaw was found in GNU patch. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by supplying a specially crafted patch file. The improper validation of hunk (single block of changes in diff) line offsets in unified-diff input can lead to an effectively infinite processing loop, resulting in excessive CPU consumption and making the utility unresponsive, requiring manual termination."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-10T00:00:00Z",
        "advisory": "RHSA-2026:37468",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "patch-main-2.8-4.2.hum1",
        "impact": "moderate"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56289\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56289\nhttps://cert.pl/en/posts/2026/07/CVE-2026-56288\nhttps://cgit.git.savannah.gnu.org/cgit/patch.git/\nhttps://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=faba04ef4f2b410257f76c1b9dc85e350929c4b9"
    ],
    "name": "CVE-2026-56289",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-24T07:44:54Z",
    "bugzilla": {
      "description": "coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values",
      "id": "2506694",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506694"
    },
    "cvss3": {
      "cvss3_base_score": "4.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d",
      "A flaw was found in GNU coreutils, specifically in the `unexpand` utility. This vulnerability, a heap-based buffer overflow, occurs due to an integer overflow when `unexpand` processes unusually large tab stop values provided by a local attacker. This can lead to an undersized memory buffer, allowing subsequent operations to write beyond its boundaries. Successful exploitation can cause the `unexpand` utility to crash, potentially resulting in a denial of service or enabling further memory manipulation."
    ],
    "statement": "A Moderate impact heap-based buffer overflow flaw was found in the `unexpand` utility of GNU coreutils. This vulnerability arises from an integer overflow when processing unusually large tab stop values, leading to an undersized buffer. A local attacker could exploit this by providing crafted input, causing the utility to crash and potentially leading to a denial of service or arbitrary memory manipulation.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHBA-2026:47115",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "coreutils-0:8.30-20.el8_10"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40724",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "coreutils-main-9.11-5.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "coreutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "coreutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "coreutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "coreutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56392\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56392\nhttps://cert.pl/en/posts/2026/07/CVE-2026-56391\nhttps://git.savannah.gnu.org/cgit/coreutils.git/\nhttps://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"
    ],
    "name": "CVE-2026-56392",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-21T15:43:55Z",
    "bugzilla": {
      "description": "libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts",
      "id": "2491186",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491186"
    },
    "cvss3": {
      "cvss3_base_score": "6.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "libexpat before 2.8.2 has an integer overflow in storeAtts.",
      "A flaw was found in libexpat. An integer overflow vulnerability exists in the `storeAtts` function. This flaw could allow an attacker to corrupt memory, leading to a denial of service, information disclosure, or potentially arbitrary code execution, compromising the integrity and confidentiality of data."
    ],
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Fix deferred",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Under investigation",
        "package_name": "compat-expat1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Under investigation",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Under investigation",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "libexpat-2.dll",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56403\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56403\nhttps://github.com/libexpat/libexpat/pull/1232"
    ],
    "name": "CVE-2026-56403",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-21T15:45:55Z",
    "bugzilla": {
      "description": "libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding",
      "id": "2491185",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491185"
    },
    "cvss3": {
      "cvss3_base_score": "6.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "libexpat before 2.8.2 has an integer overflow in addBinding.",
      "A flaw was found in libexpat. This vulnerability, an integer overflow in the `addBinding` function, could allow a local attacker to execute arbitrary code. By exploiting this, an attacker could gain control over the affected system, compromising its confidentiality and integrity."
    ],
    "statement": "This Moderate impact flaw in libexpat, an XML parsing library, could lead to arbitrary code execution through an integer overflow in the `addBinding` function. Exploitation requires local access and high attack complexity, which limits its immediate risk in standard Red Hat deployments. The vulnerability primarily affects applications that process untrusted XML data.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:40486",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "expat-main-2.8.2-1.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "compat-expat1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "xmlrpc-c",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56404\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56404\nhttps://github.com/libexpat/libexpat/pull/1249"
    ],
    "name": "CVE-2026-56404",
    "mitigation": {
      "value": "Do not process untrusted or unvalidated XML with libexpat-based applications. Enforce strict maximum size limits on XML input and namespace URI lengths before parsing",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-21T15:47:13Z",
    "bugzilla": {
      "description": "libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow",
      "id": "2491188",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491188"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
      "A flaw was found in libexpat. An integer overflow vulnerability exists within the `getAttributeId` function. This flaw could allow an attacker to potentially disclose sensitive information or execute arbitrary code, leading to a compromise of the system's integrity and confidentiality."
    ],
    "statement": "The moderate vulnerability in libexpat's `getAttributeId` function could allow a local attacker to achieve information disclosure or arbitrary code execution due to an integer overflow. The high attack complexity and local access required inherently mitigate the opportunity for successful exploitation. However, successful exploitation could compromise system integrity and confidentiality in Red Hat products that process untrusted XML input using libexpat.",
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Fix deferred",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "compat-expat1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "libexpat-2.dll",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56405\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56405\nhttps://github.com/libexpat/libexpat/pull/1251"
    ],
    "name": "CVE-2026-56405",
    "mitigation": {
      "value": "To mitigate this issue, Red Hat recommends avoiding the processing of untrusted or unvalidated XML input with applications utilizing libexpat. Implementing strict input validation and sanitization for all XML data originating from untrusted sources can reduce the risk of exploitation. This operational control helps prevent the vulnerable `getAttributeId` function from processing malicious input.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-21T15:48:21Z",
    "bugzilla": {
      "description": "libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer",
      "id": "2491187",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491187"
    },
    "cvss3": {
      "cvss3_base_score": "6.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
      "A flaw was found in libexpat. An integer overflow vulnerability exists in the `XML_ParseBuffer` function due to a missing check. This flaw could allow an attacker to cause memory corruption, potentially leading to arbitrary code execution, information disclosure, or a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56406\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56406\nhttps://github.com/libexpat/libexpat/pull/1255"
    ],
    "name": "CVE-2026-56406",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-21T15:49:35Z",
    "bugzilla": {
      "description": "libexpat: libexpat: Arbitrary code execution due to integer overflow",
      "id": "2491184",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491184"
    },
    "cvss3": {
      "cvss3_base_score": "6.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.",
      "An integer overflow exists in libexpat's doProlog function due to improper handling of entity value lengths. A local attacker could exploit this to execute arbitrary code or access sensitive system data."
    ],
    "statement": "This Moderate severity flaw in libexpat, an XML parsing library, is due to an integer overflow during the processing of entity declarations. While exploitation could lead to arbitrary code execution or information disclosure, the attack requires local access and has high complexity, limiting its immediate impact on typical Red Hat deployments.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:40486",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "expat-main-2.8.2-1.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "compat-expat1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "xmlrpc-c",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "firefox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "thunderbird",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56407\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56407\nhttps://github.com/libexpat/libexpat/pull/1262"
    ],
    "name": "CVE-2026-56407",
    "mitigation": {
      "value": "To prevent exploitation explicitly disable all internal and external XML entity processing within your application's parser configuration. Additionally, use a Web Application Firewall (WAF) to strictly limit the maximum size of incoming XML payloads to prevent the overflow trigger.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-14T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "libexpat before 2.8.2 has an integer overflow in copyString."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56408\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56408"
    ],
    "name": "CVE-2026-56408",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-14T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56409\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56409"
    ],
    "name": "CVE-2026-56409",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-21T15:55:00Z",
    "bugzilla": {
      "description": "libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.",
      "id": "2491181",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491181"
    },
    "cvss3": {
      "cvss3_base_score": "6.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.",
      "A flaw was found in libexpat. Specifically, the `xmlwf` utility contains an integer overflow vulnerability in its `resolveSystemId` function. This flaw could be exploited by an attacker to potentially gain unauthorized access to sensitive information or execute arbitrary code, leading to a compromise of the system's integrity and confidentiality."
    ],
    "statement": "This Moderate impact vulnerability in `libexpat`'s `xmlwf` utility, an integer overflow in `resolveSystemId`, could lead to information disclosure or arbitrary code execution. Exploitation requires local access and high attack complexity. Red Hat products that process untrusted XML input via `xmlwf`, including certain components of Red Hat Ansible Automation Platform and Red Hat OpenShift AI, are potentially affected.",
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Fix deferred",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56410\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56410\nhttps://github.com/libexpat/libexpat/pull/1252"
    ],
    "name": "CVE-2026-56410",
    "mitigation": {
      "value": "To reduce the risk associated with this vulnerability, avoid processing untrusted or maliciously crafted XML files using the `xmlwf` utility. Ensure that `xmlwf` is only invoked with XML data from known and trusted sources.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-21T15:56:42Z",
    "bugzilla": {
      "description": "expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution",
      "id": "2491202",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491202"
    },
    "cvss3": {
      "cvss3_base_score": "6.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.",
      "A flaw was found in libexpat, a software library used for parsing XML (Extensible Markup Language) documents. An attacker could exploit an integer overflow vulnerability in the `xmlwf` utility by crafting malicious `NOTATION` declarations. This could lead to the disclosure of sensitive information or potentially allow the attacker to execute unauthorized code, impacting the confidentiality and integrity of data."
    ],
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Fix deferred",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56411\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56411\nhttps://github.com/libexpat/libexpat/pull/1263"
    ],
    "name": "CVE-2026-56411",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-21T15:58:59Z",
    "bugzilla": {
      "description": "libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections",
      "id": "2491203",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491203"
    },
    "cvss3": {
      "cvss3_base_score": "4.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
      "A flaw was found in libexpat. This vulnerability, present in versions before 2.8.2, stems from improper handling of XML CDATA sections, where the library fails to adequately track the depth of handler calls. This can result in a 'use-after-free' error, a type of memory corruption that could allow an attacker to crash the application or potentially gain unauthorized control."
    ],
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Fix deferred",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "expat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56412\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56412\nhttps://github.com/libexpat/libexpat/pull/1278"
    ],
    "name": "CVE-2026-56412",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-22T13:10:24Z",
    "bugzilla": {
      "description": "unbound: Unbound: Heap buffer overflow via malformed DNSSEC record",
      "id": "2506137",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506137"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the default. This leads to heap buffer overflow and on a release build the outcome relies heavily on the contents of the buffer tail and the adjacent heap chunk.",
      "A vulnerability in Unbound allows remote attackers using malicious DNSSEC-signed servers to send malformed records that trigger a heap buffer overflow. This can cause a denial of service or potential limited information disclosure."
    ],
    "statement": "This Moderate impact flaw in Unbound allows a remote attacker to trigger a heap buffer overflow by providing specially crafted DNSSEC records from a malicious authoritative server. This can lead to a denial of service for the Unbound service or potentially limited information disclosure. Exploitation requires the Unbound DNSSEC validator to process malformed records, which may be exacerbated if `msg-buffer-size` is configured below its default value.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43588",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "unbound-main-1.25.2-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "unbound",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56416\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56416\nhttps://www.nlnetlabs.nl/downloads/unbound/CVE-2026-56416.txt"
    ],
    "name": "CVE-2026-56416",
    "mitigation": {
      "value": "To mitigate this issue, consider disabling DNSSEC validation in Unbound if it is not strictly required for your environment. This can be achieved by ensuring `module-config: \"iterator\"` is used in `unbound.conf` and that no `trust-anchor` or `auto-trust-anchor-file` directives are present. Disabling DNSSEC validation will reduce the security assurances provided by DNSSEC. Alternatively, configure Unbound to only perform DNSSEC validation for trusted zones. A restart of the Unbound service is required for changes to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-15T14:33:46Z",
    "bugzilla": {
      "description": "nginx: NGINX: Heap buffer over-read allows memory modification or denial of service",
      "id": "2500960",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500960"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process.\nImpact:\nThis vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A vulnerability in NGINX's ngx_http_ssi_module allows an unauthenticated MITM attacker to trigger a heap buffer over-read by manipulating upstream server responses. This requires SSI, proxy_pass, and proxy_buffering off to be configured, and can result in memory modification or a Denial of Service (DoS)."
    ],
    "statement": "This Moderate severity vulnerability in NGINX affects configurations utilizing the `ngx_http_ssi_module` alongside `proxy_pass` and `proxy_buffering off`. Exploitation requires an unauthenticated man-in-the-middle attacker to control upstream server responses, leading to limited memory modification or a worker process restart. The specific combination of directives and an active MITM position limits the overall impact.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59220",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "nginx-2:1.26.3-6.el10_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59216",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nginx:1.24-8100020260809162034.489197e6"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-26T00:00:00Z",
        "advisory": "RHSA-2026:46012",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nginx-main-1.30.4-2.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "nginx:1.24/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "nginx:1.26/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Lightspeed proxy 1",
        "fix_state": "Affected",
        "package_name": "insights-proxy/insights-proxy-container-rhel9",
        "cpe": "cpe:/a:redhat:insights_proxy:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56434\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56434\nhttps://my.f5.com/manage/s/article/K000162098"
    ],
    "name": "CVE-2026-56434",
    "mitigation": {
      "value": "To prevent exploitation, avoid configuring NGINX with `ngx_http_ssi_module` when `proxy_pass` and `proxy_buffering off` are simultaneously active. If Server-Side Includes (SSI) are not essential, disable the `ngx_http_ssi_module` by removing or commenting out the `ssi on;` directive. Alternatively, ensure `proxy_buffering` is explicitly enabled (`proxy_buffering on;`) when `proxy_pass` is used with SSI. A reload or restart of the NGINX service is necessary for configuration changes to apply, which may cause a brief service interruption.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-19T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-56968\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-56968"
    ],
    "name": "CVE-2026-56968",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-06T13:36:20Z",
    "bugzilla": {
      "description": "tar: tar: Hidden file injection via crafted archives",
      "id": "2455360",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455360"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N",
      "status": "draft"
    },
    "cwe": "CWE-434",
    "details": [
      "A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.",
      "A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."
    ],
    "acknowledgement": "Red Hat would like to thank Guillermo de Angel Garcia for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tar",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "tar",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "tar",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "tar",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "tar",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Affected",
        "package_name": "tar",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-5704\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5704"
    ],
    "name": "CVE-2026-5704",
    "mitigation": {
      "value": "To mitigate this issue, avoid extracting archives from untrusted sources. If processing untrusted archives is necessary, do so within a sandboxed environment to limit potential impact.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-23T16:40:22Z",
    "bugzilla": {
      "description": "libidn: GNU libidn: Out-of-bounds read in ToUnicode APIs",
      "id": "2491878",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491878"
    },
    "cvss3": {
      "cvss3_base_score": "2.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.",
      "A flaw was found in GNU libidn. This vulnerability allows an attacker to cause out-of-bounds reads of uninitialized memory within the ToUnicode APIs due to mishandling in the `idna_to_unicode_internal` function. This could lead to information disclosure or a denial of service."
    ],
    "statement": "This flaw resides in GNU libidn's idna_to_unicode_internal() function, used by the idna_to_unicode_* API family. The function assumes its internal ToASCII comparison buffer always begins with the \"xn--\" ACE prefix. When a decoded label is pure ASCII and shorter than four characters, no prefix is added, and the round-trip verification instead reads past the buffer's null terminator into uninitialized stack memory. Under certain call sequences that leave matching residual data on the stack, this allows an ACE-encoded label that should fail validation to be silently accepted and normalized to a different, shorter string, which could affect domain-based security decisions (allow/deny-list matching, hostname comparisons, routing, logging) made by applications relying on the result.\nThis flaw does not affect libidn2. Its round-trip verification in lookup.c never assumes the \"xn--\" prefix is present on caller-supplied data; every prefix-relative offset is either guarded by an explicit prefix check beforehand or applied to a buffer the function itself just wrote the prefix into, and it compares the full label rather than a bare suffix.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42125",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libidn2-main-2.3.8-4.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Fix deferred",
        "package_name": "libidn",
        "cpe": "cpe:/a:redhat:rhmt:1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "libidn2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libidn",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libidn",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libidn",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "libidn2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "libidn2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "moderate"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-57053\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-57053\nhttps://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html\nhttps://lists.gnu.org/archive/html/help-libidn/2026-06/msg00001.html"
    ],
    "name": "CVE-2026-57053",
    "mitigation": {
      "value": "No configuration-level mitigation is available; triggering the incorrect result depends on uninitialized stack content from earlier processing, so behavior is non-deterministic and cannot be reliably suppressed via input filtering. Users should update to a fixed libidn package once available. Applications that must process untrusted internationalized domain names before a fix is available should treat output of idna_to_unicode_8z8z()/idna_to_unicode_8zlz() as unverified, perform an independent comparison against the original ACE-encoded input, or use libidn2 for IDNA processing, which is not affected.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-13T15:38:20Z",
    "bugzilla": {
      "description": "perl: Perl: Information disclosure via integer overflow in pack/unpack operations",
      "id": "2499729",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499729"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller.",
      "A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."
    ],
    "statement": "Red Hat is aware of this vulnerability in Perl's pack and unpack built-in functions. Exploitation requires an application to pass attacker-controlled data as a pack or unpack template, which is an uncommon programming pattern. In typical usage, templates are hardcoded in source code and not derived from untrusted input, which significantly limits the practical exploitability of this flaw.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39997",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "perl-main-1.03-524.3.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "perl:5.32/perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-57432\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-57432\nhttps://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch\nhttps://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch"
    ],
    "name": "CVE-2026-57432",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-13T15:37:04Z",
    "bugzilla": {
      "description": "Storable: Storable: Denial of Service via signed integer overflow in deserialization",
      "id": "2499728",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499728"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.",
      "A flaw was found in Storable. This vulnerability allows a remote attacker to cause a denial of service (DoS) by providing a specially crafted data blob during deserialization. The flaw occurs due to a signed integer overflow when processing an SX_HOOK record, leading to a negative count being passed to an internal function, which then causes the application to terminate unexpectedly."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "perl-Storable",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "important"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-57433\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-57433\nhttps://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch"
    ],
    "name": "CVE-2026-57433",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-25T15:27:50Z",
    "bugzilla": {
      "description": "vim: Vim: Out-of-bounds Read with libsodium-encrypted Files",
      "id": "2492979",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492979"
    },
    "cvss3": {
      "cvss3_base_score": "4.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04! or VimCrypt~05!\nmethod (xchacha20poly1305, requires the +sodium feature) whose body is shorter than a single libsodium secretstream header, an unsigned length calculation underflows and a subsequent decryption call reads far past the end of the input buffer, crashing Vim. This vulnerability is fixed in 9.2.0671.",
      "A flaw was found in Vim, an open source command-line text editor. When opening a specially crafted encrypted file using the VimCrypt~04! or VimCrypt~05! methods, an attacker could trigger an unsigned length calculation error. This issue leads to an out-of-bounds read, causing Vim to crash and resulting in a denial of service."
    ],
    "statement": "This Moderate impact vulnerability in Vim arises from an out-of-bounds read when processing a specially crafted libsodium-encrypted file. If a user opens a malicious file encrypted with VimCrypt~04! or VimCrypt~05! and the file body is shorter than a single libsodium secretstream header, Vim may crash. This issue requires user interaction to open a malformed file and the +sodium feature to be enabled, limiting its exploitability in typical Red Hat environments.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-26T00:00:00Z",
        "advisory": "RHSA-2026:30267",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "vim-main-9.2.725-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-57452\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-57452\nhttps://github.com/vim/vim/commit/c8777cec25dcfae89c42e9aff51af61f71c5745f\nhttps://github.com/vim/vim/releases/tag/v9.2.0671\nhttps://github.com/vim/vim/security/advisories/GHSA-c4j9-wr9j-4486"
    ],
    "name": "CVE-2026-57452",
    "mitigation": {
      "value": "Ensure the spell checker is turned off by running :set nospell within Vim. Do not open untrusted or suspicious files—particularly those encrypted with libsodium methods (VimCrypt~04! or VimCrypt~05!)—within the Vim editor. This prevents the execution of the vulnerable decryption routine",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-25T15:22:37Z",
    "bugzilla": {
      "description": "vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo()",
      "id": "2492968",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492968"
    },
    "cvss3": {
      "cvss3_base_score": "4.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loop advances the output index ri with no upper bound and terminates only on the input NUL, writing one byte per input byte into the MAXWLEN-element stack buffer the caller provides. A word longer than MAXWLEN, passed to soundfold() (or reached via sound-based spell suggestion) while a SOFO-based spell language is active, therefore writes past the end of that buffer. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0698.",
      "A memory corruption flaw in Vim allows an attacker to cause a Denial of Service (DoS). When a SOFO-based spell language is active, providing an excessively long word to the spell checker triggers a stack out-of-bounds write in the spell_soundfold_sofo() function, causing the editor to crash."
    ],
    "statement": "This Moderate impact flaw in Vim, a command-line text editor, is due to a stack out-of-bounds write in the spell checker. Exploitation requires a user to open a specially crafted file or encounter a long word via spell suggestion while a SOFO-based spell language is active, leading to a Denial of Service. This is not a default configuration in most Red Hat environments, limiting the attack surface.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48650",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "vim-2:9.1.083-9.el10_2.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55431",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48703",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-31.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48703",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-31.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47982",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47982",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.13"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54769",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202608130832-0"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-26T00:00:00Z",
        "advisory": "RHSA-2026:30267",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "vim-main-9.2.725-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1786435241"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1786533457"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1786533449"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1786435483"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1786533529"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-57455\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-57455\nhttps://github.com/vim/vim/commit/497f931f85339d175d7f69588dd249e8ccfed41b\nhttps://github.com/vim/vim/releases/tag/v9.2.0698\nhttps://github.com/vim/vim/security/advisories/GHSA-q8mh-6qm3-25g4"
    ],
    "name": "CVE-2026-57455",
    "mitigation": {
      "value": "To mitigate this issue disable spell checking or avoid using SOFO-based spell files. This can be achieved globally by adding set nospell to your ~/.vimrc configuration file. Ensure your systems utilize standard UTF-8 encoding. This flaw is strictly confined to legacy 8-bit encodings and cannot be triggered under default Red Hat configurations.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-25T15:16:16Z",
    "bugzilla": {
      "description": "vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion",
      "id": "2492972",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492972"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-94",
    "details": [
      "Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.",
      "There is a security flaw in Vim. If you use Vim to open a malicious file written by a hacker, and you use the auto-complete feature while typing, the file can secretly force your computer to run unauthorized commands or malware."
    ],
    "statement": "This flaw is rated as Important. A vulnerability in Vim's Python omni-completion feature allows for arbitrary code execution. By opening a specially crafted file, a local attacker could execute arbitrary Python code due to improper handling of docstrings during omni-completion, leading to a compromise of the system where Vim is running.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48650",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "vim-2:9.1.083-9.el10_2.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55431",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48703",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-31.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48703",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-31.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47982",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47982",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.13"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54769",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202608130832-0"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-03T00:00:00Z",
        "advisory": "RHSA-2026:35387",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "vim-main-9.2.780-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1786435241"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1786533457"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1786533449"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1786435483"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1786533529"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-57456\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-57456\nhttps://github.com/vim/vim/commit/cce141c42740f122dd8486ae04e21c2a81016ba8\nhttps://github.com/vim/vim/releases/tag/v9.2.0699\nhttps://github.com/vim/vim/security/advisories/GHSA-ppj8-wqjf-6fp3"
    ],
    "name": "CVE-2026-57456",
    "mitigation": {
      "value": "To mitigate this vulnerability, users should avoid opening untrusted Python files or using Python omni-completion on such files. If Python omni-completion is not required, it can be disabled by adding `autocmd FileType python setlocal omnifunc=` to your `.vimrc` file. This will prevent the vulnerable code from being executed. Disabling Python omni-completion will remove the ability to use `Ctrl-X Ctrl-O` for Python code completion. A restart of Vim is required for the changes to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-05T14:49:19Z",
    "bugzilla": {
      "description": "django: Django: Service degradation via understated Content-Length header in ASGI requests",
      "id": "2466776",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466776"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-770",
    "details": [
      "An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.\nASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation.\nAs a reminder, Django expects a limit to be configured at the web server level rather than solely relying on `FILE_UPLOAD_MAX_MEMORY_SIZE`.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Kyle Agronick for reporting this issue.",
      "A flaw was found in Django. This vulnerability allows a remote attacker to bypass the FILE_UPLOAD_MAX_MEMORY_SIZE limit by sending specially crafted ASGI (Asynchronous Server Gateway Interface) requests with a missing or understated Content-Length header. This can lead to large files being loaded into memory, potentially causing service degradation or a Denial of Service (DoS) condition."
    ],
    "statement": "This Moderate flaw in Django can lead to service degradation or a denial of service. A remote attacker can exploit this by sending ASGI requests with a manipulated Content-Length header, bypassing the FILE_UPLOAD_MAX_MEMORY_SIZE and causing large files to be loaded into memory. Red Hat advises implementing content length restrictions at the web server layer, as Django's internal limits are not solely relied upon for protection.",
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "python-django20",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite-capsule:el8/python-django",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite:el8/python-django",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Update Infrastructure 4 for Cloud Providers",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:rhui:4::el8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-5766\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5766\nhttps://docs.djangoproject.com/en/dev/releases/security/\nhttps://groups.google.com/g/django-announce\nhttps://www.djangoproject.com/weblog/2026/may/05/security-releases/"
    ],
    "name": "CVE-2026-5766",
    "mitigation": {
      "value": "To mitigate this issue, configure the web server (e.g., Nginx, Apache) hosting the Django application to enforce strict Content-Length limits for incoming ASGI requests. This ensures that large files cannot be loaded into memory by bypassing Django's internal FILE_UPLOAD_MAX_MEMORY_SIZE setting. Consult your web server's documentation for specific configuration instructions on limiting request body size. A service reload or restart may be required for the changes to take effect, which could temporarily impact service availability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-29T00:00:00Z",
    "bugzilla": {
      "description": "curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse",
      "id": "2461201",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461201"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-1025",
    "details": [
      "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different 'share' than the new subsequent transfer\nshould.\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
      "A flaw was found in libcurl. Due to a logical error in the connection reuse mechanism for SMB (Server Message Block) transfers, libcurl might reuse an existing SMB connection with a different share than intended. This vulnerability, categorized as CWE-488 (Exposure of Data Element to Wrong Session), could lead to the download of an incorrect file or the upload of a file to an unintended location when an application uses libcurl for SMB transfers."
    ],
    "statement": "This Moderate impact flaw in libcurl affects applications performing SMB transfers. A logical error in the SMB connection reuse mechanism can lead to unintended file downloads or uploads to incorrect locations. This impacts applications that rely on libcurl for secure and accurate SMB file operations.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:12916",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.20.0-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Fix deferred",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-5773\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5773\nhttps://curl.se/docs/CVE-2026-5773.html"
    ],
    "name": "CVE-2026-5773",
    "mitigation": {
      "value": "To mitigate this issue, avoid using SMB for transfers with libcurl. As SMB support is opt-in since curl 8.20.0 and SMBv1 is deprecated, ensuring SMB functionality is disabled or not utilized in applications leveraging libcurl will prevent exposure. If SMB is required, consider upgrading to curl 8.20.0 or later, which addresses this flaw by preventing SMB connection reuse.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-26T00:00:00Z",
    "bugzilla": {
      "description": "glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()",
      "id": "2492243",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-126",
    "details": [
      "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
      "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."
    ],
    "statement": "Any applications calling the `g_variant_is_normal_form()`, `g_variant_get_normal_form()` or `g_variant_byteswap()` functions that process untrusted GVariant data received from D-Bus, network or file are vulnerable to this issue. This flaw can cause an out-of-bounds read of only 1 byte, leading to an information disclosure of only 1 byte and a denial of service when the out-of-bounds read crosses a page boundary. Due to these reasons, this vulnerability has been rated with a moderate severity.",
    "acknowledgement": "Red Hat would like to thank linhlhq for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57015",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "glib2-0:2.80.4-12.el10_2.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49512",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "mingw-glib2-0:2.70.1-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55440",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55440",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.9"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "glib2",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-58010\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58010\nhttps://gitlab.gnome.org/GNOME/glib/-/issues/3915"
    ],
    "name": "CVE-2026-58010",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-27T00:00:00Z",
    "bugzilla": {
      "description": "glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime",
      "id": "2492245",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
      "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."
    ],
    "statement": "Any applications that allow a user to submit a date to `g_date_time_add_full()` and later call any getter functions, such as `g_date_time_get_month()` or `g_date_time_get_year()`, with the returned GDateTime object are vulnerable to this issue. This flaw can cause an out-of-bounds read of only 2 bytes, leading to a denial of service due to logic errors that a corrupted date can trigger. Due to these reasons, this vulnerability has been rated with a moderate severity.",
    "acknowledgement": "Red Hat would like to thank linhlhq for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57015",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "glib2-0:2.80.4-12.el10_2.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49512",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "mingw-glib2-0:2.70.1-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55440",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55440",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.9"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "glib2",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-58011\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58011\nhttps://gitlab.gnome.org/GNOME/glib/-/issues/3917"
    ],
    "name": "CVE-2026-58011",
    "mitigation": {
      "value": "To mitigate this vulnerability, in applications processing user-supplied dates, implement input validation to ensure the supplied date is within the supported range before calling g_date_time_add_full() with untrusted data, specifically rejecting inputs that result in a negative or zero days field.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-03-27T00:00:00Z",
    "bugzilla": {
      "description": "glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()",
      "id": "2492247",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-126",
    "details": [
      "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
      "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."
    ],
    "statement": "Any applications that use g_regex_replace() or g_regex_replace_eval() with the G_REGEX_RAW compile flag and allow user-controlled replacement strings containing case-change escapes (\\u, \\l, \\U, \\L) are vulnerable to this issue. This flaw can cause a buffer over-read of 1-5 bytes, leading to a minor information disclosure and a denial of service when the buffer over-read crosses a page boundary. Due to these reasons, this vulnerability has been rated with a moderate severity.",
    "acknowledgement": "Red Hat would like to thank linhlhq for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57015",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "glib2-0:2.80.4-12.el10_2.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49512",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "mingw-glib2-0:2.70.1-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55440",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55440",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.9"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "glib2",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-58012\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58012\nhttps://gitlab.gnome.org/GNOME/glib/-/issues/3918"
    ],
    "name": "CVE-2026-58012",
    "mitigation": {
      "value": "To mitigate this vulnerability, implement strict input validation to sanitize user-supplied replacement strings, specifically rejecting or escaping case-change modifiers (\\u, \\l, \\U, \\L) before calling g_regex_replace() or g_regex_replace_eval() when the G_REGEX_RAW compile flag is used. Removing the G_REGEX_RAW flag or hardcoding the replacement strings will completely neutralize this issue.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-07T00:00:00Z",
    "bugzilla": {
      "description": "glib: off-by-one error in glib/gkeyfile.c via \"g_key_file_get_locale_string_list\"",
      "id": "2492255",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-193",
    "details": [
      "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
      "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."
    ],
    "statement": "Any applications loading or parsing untrusted key files, typically .desktop or .ini files, are vulnerable to this issue. This flaw can cause an off-by-one error, leading to an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary. Due to these reasons, this vulnerability has been rated with a moderate severity.",
    "acknowledgement": "Red Hat would like to thank linhlhq for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57015",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "glib2-0:2.80.4-12.el10_2.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49512",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "mingw-glib2-0:2.70.1-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55440",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55440",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.9"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "glib2",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-58014\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58014\nhttps://gitlab.gnome.org/GNOME/glib/-/issues/3930"
    ],
    "name": "CVE-2026-58014",
    "mitigation": {
      "value": "To mitigate this vulnerability, implement input validation to sanitize untrusted key files (such as .desktop or .ini files), specifically rejecting or stripping empty values before calling g_key_file_get_locale_string_list(). Alternatively, restricting the application to only load key files from trusted sources will completely neutralize this issue.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-08T00:00:00Z",
    "bugzilla": {
      "description": "glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive",
      "id": "2492256",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-22",
    "details": [
      "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
      "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."
    ],
    "statement": "To exploit this flaw, an attacker must be in a position to perform a man-in-the-middle (MitM) attack on the connection or operate a malicious server that the client connects to. Furthermore, extracting data requires an oracle attack (guessing and hashing), increasing the complexity of exploitation. However, if successful, this issue allows the exfiltration of sensitive secrets, such as SSH keys or API tokens, from the filesystem. Due to these reasons, this vulnerability has been rated with a moderate severity.",
    "acknowledgement": "Red Hat would like to thank Thepwnisher for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:57015",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "glib2-0:2.80.4-12.el10_2.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49512",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "mingw-glib2-0:2.70.1-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55440",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55440",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.9"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "glib2",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-58015\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58015\nhttps://gitlab.gnome.org/GNOME/glib/-/issues/3931"
    ],
    "name": "CVE-2026-58015",
    "mitigation": {
      "value": "To mitigate this vulnerability, ensure that applications only connect to trusted D-Bus servers and operate within secure, isolated networks to prevent man-in-the-middle (MitM) attacks. If feasible, configuring the D-Bus connection to strictly require the EXTERNAL authentication mechanism and disabling DBUS_COOKIE_SHA1 will completely neutralize this issue.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-04-08T00:00:00Z",
    "bugzilla": {
      "description": "glib: integer underflow in gio/gdbusintrospection.c via \"g_dbus_node_info_new_for_xml\"",
      "id": "2492257",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492257"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-191",
    "details": [
      "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
      "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."
    ],
    "statement": "Any applications processing D-Bus introspection XML input from untrusted sources with g_dbus_node_info_new_for_xml() are vulnerable to this issue. In GLib itself, the gdbus command line tool is the primary vector for local exploitation. However, other applications using the vulnerable function may process untrusted input in a way that allows a remote attacker to trigger this flaw. This vulnerability can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service. As this vulnerability allows a remote attacker to cause a denial of service, it has been rated with an important severity.",
    "acknowledgement": "Red Hat would like to thank linhlhq for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42063",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "glib2-0:2.80.4-12.el10_2.14"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51185",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "glib2-0:2.80.4-4.el10_0.10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51183",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "glib2-0:2.56.1-13.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:49512",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::crb",
        "package": "mingw-glib2-0:2.70.1-9.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42090",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "glib2-0:2.56.4-170.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51184",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "glib2-0:2.56.4-10.el8_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51184",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "glib2-0:2.56.4-10.el8_4.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51181",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "glib2-0:2.56.4-158.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51181",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "glib2-0:2.56.4-158.el8_6.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51182",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "glib2-0:2.56.4-165.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51182",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "glib2-0:2.56.4-165.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42089",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42089",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glib2-0:2.68.4-19.el9_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51176",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "glib2-0:2.68.4-7.el9_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51177",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "glib2-0:2.68.4-14.el9_4.7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-06T00:00:00Z",
        "advisory": "RHSA-2026:51175",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "glib2-0:2.68.4-16.el9_6.6"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46836",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1784821670"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46836",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1784821750"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1784794818"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1784794778"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1784795112"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1784794289"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1784795076"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Will not fix",
        "package_name": "mingw-glib2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "glib2",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-58016\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58016\nhttps://gitlab.gnome.org/GNOME/glib/-/issues/3932"
    ],
    "name": "CVE-2026-58016",
    "mitigation": {
      "value": "To mitigate this vulnerability, implement input validation to sanitize untrusted D-Bus introspection XML, specifically rejecting malformed structures such as <node> elements improperly nested within <method>, <signal>, <property> or <arg> elements before calling g_dbus_node_info_new_for_xml(). Alternatively, restricting the application to only process XML input from trusted, authenticated sources will completely neutralize this issue.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-28T01:32:53Z",
    "bugzilla": {
      "description": "libssh2: libssh2: Heap buffer overflow via integer overflow in publickey attribute allocation",
      "id": "2493955",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493955"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.",
      "A flaw in libssh2 allows a malicious SSH server to trigger a memory overflow by sending a manipulated attribute count. This can cause the connecting client to crash or allow unauthorized code execution."
    ],
    "statement": "This Moderate impact flaw in libssh2 allows a malicious SSH server to trigger a heap buffer overflow in a connecting client. By manipulating the publickey-subsystem response, an attacker could cause an integer overflow, potentially leading to denial of service or arbitrary code execution on Red Hat systems using libssh2 to establish SSH connections.\nNote: Red Hat Enterprise Linux (RHEL) 8 and newer are not affected by this flaw, as they do not ship the libssh2 package.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54070",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libssh2-main-1.11.1-10.4.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-58050\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58050\nhttps://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc\nhttps://github.com/libssh2/libssh2/blob/master/src/publickey.c\nhttps://www.vulncheck.com/advisories/libssh2-integer-overflow-in-publickey-subsystem-attribute-allocation"
    ],
    "name": "CVE-2026-58050",
    "mitigation": {
      "value": "To mitigate this issue,ensure your applications are running strictly on 64-bit architectures, which naturally prevents the integer overflow from occurring. Additionally, configure your applications to connect only to trusted, verified SSH servers.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-28T01:32:57Z",
    "bugzilla": {
      "description": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
      "id": "2493954",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493954"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-444",
    "details": [
      "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.",
      "A flaw in nghttp2's nghttpx proxy allows a remote attacker to perform HTTP request smuggling and cross-client response-queue poisoning. This occurs because the proxy ambiguously forwards HTTP/1.1 Upgrade requests that contain a Content-Length header to reusable keep-alive backend connections."
    ],
    "statement": "A flaw in nghttp2's nghttpx proxy allows remote HTTP request smuggling and cross-client response poisoning by forwarding malformed HTTP/1.1 Upgrade requests containing a Content-Length body. This is rated Moderate because successful exploitation requires high attack complexity on the backend server.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54650",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "nghttp2-0:1.68.0-3.el10_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55804",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "nghttp2-0:1.33.0-6.el8_10.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54662",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "nghttp2-0:1.43.0-6.el9_8.2"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-03T00:00:00Z",
        "advisory": "RHSA-2026:35454",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nghttp2-main-1.69.0-3.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-17T00:00:00Z",
        "advisory": "RHSA-2026:41240",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.21.0-0.1.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52414",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nghttp2-main-1.69.0-5.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "nodejs22",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "nodejs24",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:22/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:24/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:22/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nodejs:24/nodejs",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-58055\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58055\nhttps://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc\nhttps://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e\nhttps://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"
    ],
    "name": "CVE-2026-58055",
    "mitigation": {
      "value": "Configure your WAF or load balancer to drop incoming HTTP/1.1 requests that contain both Upgrade and Content-Length headers. This blocks the malformed traffic at the edge before it can reach the vulnerable proxy without impacting legitimate users.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-28T01:32:59Z",
    "bugzilla": {
      "description": "nmap: Nmap: Denial of Service via crafted IPv6 response",
      "id": "2493951",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493951"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.",
      "A flaw was found in Nmap. A remote attacker or a scanned target can send a specially crafted IPv6 response with a truncated extension header. This can lead to an integer underflow, causing out-of-bounds reads and a denial of service (DoS) due to a crash during raw IPv6 scans."
    ],
    "statement": "Red Hat rates this flaw as Moderate rather than the AI-assigned Important severity. The Aegis AI-Bot rated UI:N (no user interaction), but nmap is a command-line scanning tool that an operator must manually invoke — initiating a scan is user interaction per the CVSS definition of UI:R. Correcting UI:N to UI:R reduces the CVSS from 7.5 to 6.5, aligning with the upstream CVEORG assessment. The vulnerability requires a scanned target or on-path attacker to return a crafted IPv6 response with a truncated extension header during a raw IPv6 scan.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "nmap",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "nmap",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "nmap",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nmap",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nmap",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-58058\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58058\nhttps://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc\nhttps://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83\nhttps://nmap.org/changelog.html\nhttps://www.vulncheck.com/advisories/nmap-integer-underflow-in-ipv6-extension-header-parsing"
    ],
    "name": "CVE-2026-58058",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-07T19:43:34Z",
    "bugzilla": {
      "description": "wget: GNU Wget: Memory corruption via crafted Metalink URL",
      "id": "2497838",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497838"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.",
      "A flaw was found in GNU Wget. A malicious server could exploit a heap buffer underread vulnerability by providing a specially crafted Metalink document containing a URL with only whitespace characters. This could lead to memory corruption and abnormal program behavior, potentially causing a denial of service."
    ],
    "statement": "Moderate: A heap-buffer-underread in GNU Wget's clean_metalink_string() function, affecting Red Hat Enterprise Linux 8, can be triggered when wget processes a specially crafted Metalink document containing a resource URL consisting only of whitespace characters. This code path is only reachable when Wget's Metalink support is explicitly requested via --input-metalink or --metalink-over-http; it is not exercised during ordinary downloads. Successful exploitation requires a user to invoke Wget's Metalink handling against an attacker-controlled or compromised server. The out-of-bounds byte is read only to decide whether to continue a trim loop and is never returned, logged, or written -- the practical impact is limited to a crash of the wget process (denial of service), not memory corruption or code execution.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-58469\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58469\nhttps://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826\nhttps://www.vulncheck.com/advisories/gnu-wget-heap-buffer-underread-via-metalink-url-parsing"
    ],
    "name": "CVE-2026-58469",
    "mitigation": {
      "value": "Avoid using Wget's Metalink options (--input-metalink and --metalink-over-http) when downloading from untrusted or unverified servers. Since Metalink processing must be explicitly requested, omitting these options avoids the vulnerable code path entirely.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-07T19:45:53Z",
    "bugzilla": {
      "description": "wget: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization",
      "id": "2497860",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497860"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
      "An integer overflow in GNU Wget's parse_content_range() function allows malicious servers to send crafted Content-Range headers. This triggers undefined behavior and download desynchronization, potentially causing a denial of service or data integrity issues for the client."
    ],
    "statement": "Moderate: GNU Wget is vulnerable to a client-side integer overflow in its Content-Range header processing. If a client connects to an attacker-controlled server, the server can return anomalous headers that cause undefined behavior and stream desynchronization. This results in local data integrity issues or a denial of service, though the impact is strictly limited to the Wget process itself.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-58470\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58470\nhttps://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf\nhttps://www.vulncheck.com/advisories/gnu-wget-integer-overflow-via-content-range-header-parsing"
    ],
    "name": "CVE-2026-58470",
    "mitigation": {
      "value": "To mitigate this issue, users should avoid using `wget` to download content from untrusted or unverified sources. When `wget` is used in automated scripts or environments, ensure that the target servers are trusted to prevent exposure to malicious `Content-Range` headers. Restricting network access for `wget` to only trusted hosts can also reduce the attack surface.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-07T19:47:47Z",
    "bugzilla": {
      "description": "wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption",
      "id": "2497850",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497850"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-122",
    "details": [
      "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
      "A flaw was found in GNU Wget. A remote attacker can exploit a heap buffer overflow vulnerability in the convert_fname() function. This occurs when processing a server-supplied filename that requires character set conversion, leading to memory corruption due to incorrect buffer reallocation. This can result in a denial of service or other impacts."
    ],
    "statement": "Moderate: A heap buffer overflow in GNU Wget, affecting Red Hat Enterprise Linux and other products, can be triggered by a remote attacker. This flaw occurs when `wget` processes a specially crafted server-supplied filename that requires character set conversion, leading to memory corruption. Successful exploitation requires user interaction with a malicious server and could result in a denial of service or potentially other impacts.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-58471\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58471\nhttps://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee\nhttps://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c"
    ],
    "name": "CVE-2026-58471",
    "mitigation": {
      "value": "To mitigate this issue, always use the -O (or --output-document) flag in your scripts to explicitly define the local filename. This forces wget to ignore the server's provided filename, completely bypassing the vulnerable code path.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-07T19:50:53Z",
    "bugzilla": {
      "description": "wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute",
      "id": "2497857",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497857"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-131",
    "details": [
      "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
      "A flaw was found in GNU Wget. A remote attacker can exploit a heap buffer overflow vulnerability in the `html_quote_string()` function by providing a specially crafted HTML attribute. This can lead to memory corruption and potentially result in arbitrary code execution or a denial of service."
    ],
    "statement": "This Moderate impact heap buffer overflow in GNU Wget occurs when processing HTML attributes with extensive entity encoding. Successful exploitation requires user interaction, as a victim must download a specially crafted HTML file, and is further constrained by high attack complexity. This limits the direct risk to Red Hat systems where Wget is typically used for trusted content retrieval.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "wget",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-58472\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58472\nhttps://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812\nhttps://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-html-attribute-encoding"
    ],
    "name": "CVE-2026-58472",
    "mitigation": {
      "value": "Users are advised to avoid retrieving content from untrusted or unverified sources using Wget.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-07-14T08:13:04Z",
    "bugzilla": {
      "description": "tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve",
      "id": "2499917",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499917"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-807",
    "details": [
      "Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.\nUsers are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.",
      "A flaw was found in Apache Tomcat. This vulnerability, located in the rewrite valve, is due to improper handling of URL encoding (hex encoding). A remote attacker could exploit this to bypass security constraints in certain configurations, potentially gaining unauthorized access or performing actions that should be restricted."
    ],
    "statement": "This Low impact vulnerability in Apache Tomcat's rewrite valve allows a security constraint bypass through improper URL encoding. Exploitation requires specific configurations and has high attack complexity, limiting its overall risk to Red Hat products.",
    "affected_release": [
      {
        "product_name": "Red Hat JBoss Web Server 7.0.1",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49952",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 10",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49951",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
        "package": "jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 8",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49951",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
        "package": "jws7-tomcat-0:11.0.21-6.redhat_00005.1.el8jws"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7.0 on RHEL 9",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:49951",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
        "package": "jws7-tomcat-0:11.0.21-6.redhat_00005.1.el9jws"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36872",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.24-0.1.hum1",
        "impact": "low"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-10T00:00:00Z",
        "advisory": "RHSA-2026:37767",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.57-1.hum1",
        "impact": "low"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Fix deferred",
        "package_name": "jws5-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Affected",
        "package_name": "jws6-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59083\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59083\nhttps://lists.apache.org/thread/3g63zos2gkjo5vgnrk8kxmosv47w6wbq"
    ],
    "name": "CVE-2026-59083",
    "mitigation": {
      "value": "To mitigate this issue, review Apache Tomcat's rewrite valve configurations. If the rewrite valve is not essential for your application, consider disabling it. If it is required, ensure its configuration does not permit improper URL encoding that could lead to security constraint bypasses. A service restart may be required for changes to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-07-14T08:24:21Z",
    "bugzilla": {
      "description": "tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations",
      "id": "2499931",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499931"
    },
    "cvss3": {
      "cvss3_base_score": "3.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-1188",
    "details": [
      "Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.\nUsers are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.",
      "A flaw was found in Apache Tomcat. Insufficient technical documentation regarding the secure configuration of the EncryptInterceptor component may lead to deployments with insecure settings. This vulnerability could allow an attacker to exploit misconfigurations that arise from unclear guidance, potentially compromising the confidentiality or integrity of data processed by the affected system."
    ],
    "statement": "This Low impact vulnerability in Apache Tomcat arises from insufficient documentation for the EncryptInterceptor. Without clear guidance on secure configuration, administrators might inadvertently deploy the interceptor in a way that weakens security, rather than a direct code flaw. This issue affects Red Hat products utilizing Apache Tomcat, including Red Hat Enterprise Linux and Red Hat JBoss Web Server.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-08T00:00:00Z",
        "advisory": "RHSA-2026:36872",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.24-0.1.hum1",
        "impact": "low"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-10T00:00:00Z",
        "advisory": "RHSA-2026:37767",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat10-main-10.1.57-1.hum1",
        "impact": "low"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "pki-deps:10.6/pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Fix deferred",
        "package_name": "jws5-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Not affected",
        "package_name": "jws6-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7",
        "fix_state": "Not affected",
        "package_name": "tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59084\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59084\nhttps://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7"
    ],
    "name": "CVE-2026-59084",
    "mitigation": {
      "value": "To mitigate this issue, ensure that the EncryptInterceptor in Apache Tomcat is configured according to secure best practices. Review existing configurations of EncryptInterceptor to verify that all security requirements are met and that no insecure settings are in place. If the EncryptInterceptor is not actively used, no specific action is required.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-20T20:37:31Z",
    "bugzilla": {
      "description": "glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings",
      "id": "2459854",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459854"
    },
    "cvss3": {
      "cvss3_base_score": "5.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
      "A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42694",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "glibc-0:2.39-128.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42733",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "glibc-0:2.28-251.el8_10.40"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42733",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "glibc-0:2.28-251.el8_10.40"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:42952",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glibc-0:2.34-274.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:42952",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glibc-0:2.34-274.el9_8"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46836",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1784821670"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46836",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1784821750"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-01T00:00:00Z",
        "advisory": "RHSA-2026:12740",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "glibc-main-2.42-12.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-gateway-opa-rhel9:1784775772"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-gateway-rhel9:1784775770"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-jaeger-query-rhel9:1784775834"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-operator-bundle:1784777166"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-query-rhel9:1784775793"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-rhel9:1784775768"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-rhel9-operator:1784775782"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50205",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/opentelemetry-collector-rhel9:1785704636"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50205",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/opentelemetry-rhel9-operator:1785704547"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1784794818"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1784794778"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1784795112"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1784794289"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1784795076"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "compat-glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "compat-glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-5928\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5928\nhttps://sourceware.org/bugzilla/show_bug.cgi?id=33998"
    ],
    "name": "CVE-2026-5928",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-19T00:00:00Z",
    "bugzilla": {
      "description": "sed: GNU sed TOCTOU race condition",
      "id": "2458960",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458960"
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-367",
    "details": [
      "When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: \n1. resolves symlink to its target and stores the resolved path for determining when output is written,\n2. opens the original symlink path (not the resolved one) to read the file. \nBetween these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1. This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process.\nThis issue was fixed in version 4.10.",
      "A Time-of-Check Time-of-Use (TOCTOU) race condition was found in GNU sed. When the -i (in-place) and --follow-symlinks options are used together, sed resolves the symlink but reopens the path for writing. An attacker with write access to the directory containing the symlink can swap it between the check and the open operations. If a privileged user executes sed in this manner on a path influenced by the attacker, it can lead to arbitrary file overwrites and potential privilege escalation."
    ],
    "statement": "This is a Moderate severity flaw in GNU sed that allows for arbitrary file overwrite. The vulnerability is a Time-of-Check Time-of-Use (TOCTOU) race condition in the `--follow-symlinks` option, enabling an attacker to cause `sed -i --follow-symlinks` to read attacker-controlled content and write it to an unintended file. Exploitation requires a privileged process to execute `sed` on a path that an attacker can influence.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-04-27T00:00:00Z",
        "advisory": "RHSA-2026:10995",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "sed-main-4.10-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "sed",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "sed",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "sed",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "sed",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "sed",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-5958\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5958"
    ],
    "name": "CVE-2026-5958",
    "mitigation": {
      "value": "To mitigate this vulnerability, avoid using the `sed -i --follow-symlinks` command in privileged contexts or on paths that can be influenced by untrusted users. This flaw specifically affects the `--follow-symlinks` option, which, when used by a privileged process on an attacker-controlled path, can lead to arbitrary file overwrite. Restricting the use of this specific option in sensitive operations can reduce the risk of exploitation.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-23T06:43:53Z",
    "bugzilla": {
      "description": "policycoreutils: Policycoreutils: Denial of Service via missing authorization in seunshares",
      "id": "2506355",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506355"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-266",
    "details": [
      "A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in\nunconfined context\nThis issue affects policycoreutils through 3.10.",
      "A flaw was found in policycoreutils through 3.10 in seunshares. Missing authorization lets a local user in an unconfined SELinux context terminate other processes that are also unconfined, including root-owned ones. That can cause denial of service by killing critical processes."
    ],
    "statement": "policycoreutils seunshares is vulnerable to missing authorization checks. A local low-privileged user running unconfined may kill other unconfined processes, including root-owned ones, causing denial of service. Affects policycoreutils through 3.10. Default confined SELinux setups reduce the practical attack surface.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44343",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "policycoreutils-main-3.11-2.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "policycoreutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "policycoreutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Under investigation",
        "package_name": "policycoreutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "policycoreutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "policycoreutils",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59677\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59677\nhttps://bugzilla.suse.com/show_bug.cgi?id=1268256\nhttps://security.opensuse.org/2026/07/15/selinux-seunshare.html"
    ],
    "name": "CVE-2026-59677",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-05T10:00:00Z",
    "bugzilla": {
      "description": "libxfont2: Font Server Client encoding[] Out-Of-Bounds Read/Write",
      "id": "2509620",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509620"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "A flaw was found in the libXfont2 font-server client. A remote attacker, by operating a malicious font server, could exploit an out-of-bounds read/write vulnerability. This occurs because the client incorrectly handles font data, leading to an out-of-bounds memory access. This can lead to privilege escalation if the X server runs with root privileges, or a denial of service (crash) if it runs as an unprivileged user."
    ],
    "statement": "This flaw in libXfont2 could lead to privilege escalation or denial of service. A remote attacker operating a malicious font server could exploit an out-of-bounds memory access in the font-server client. This is rated Important because while privilege escalation requires the X server to run as root (not a default in modern Red Hat Enterprise Linux), denial of service remains a risk for users of graphical environments who connect to untrusted font servers.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55448",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libXfont2-0:2.0.6-5.el10_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55446",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "libXfont2-0:2.0.3-2.el8_10.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55447",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "libXfont2-0:2.0.3-12.el9_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59311",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "libXfont2-0:2.0.3-12.el9_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59312",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "libXfont2-0:2.0.3-12.el9_4.3"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "libXfont2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59679\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59679"
    ],
    "name": "CVE-2026-59679",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-21T11:07:00Z",
    "bugzilla": {
      "description": "libssh: libssh: denial of service via zero advertised channel packet size",
      "id": "2498176",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498176"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-835",
    "details": [
      "A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.",
      "A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service."
    ],
    "acknowledgement": "Red Hat would like to thank Haruto Kimura, Rinku Das, and Yi Lin for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55855",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libssh-0:0.12.0-3.el10_2"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42922",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libssh-main-0.12.1-4.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59843\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59843"
    ],
    "name": "CVE-2026-59843",
    "mitigation": {
      "value": "No workaround available.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-21T11:17:49Z",
    "bugzilla": {
      "description": "libssh: libssh: denial of service via oversized SFTP read length",
      "id": "2498177",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498177"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-789",
    "details": [
      "A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.",
      "A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests."
    ],
    "acknowledgement": "Red Hat would like to thank Chanho Kim for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55855",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libssh-0:0.12.0-3.el10_2"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42922",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libssh-main-0.12.1-4.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59844\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59844"
    ],
    "name": "CVE-2026-59844",
    "mitigation": {
      "value": "No workaround available.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-21T11:23:44Z",
    "bugzilla": {
      "description": "libssh: libssh: denial of service via unchecked ProxyCommand fork() failure",
      "id": "2498178",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498178"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-390",
    "details": [
      "A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.",
      "A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service."
    ],
    "statement": "This Moderate flaw in libssh client-side ProxyCommand handling can lead to a local denial of service. When ProxyCommand is configured, an unchecked fork() failure may result in signals being sent across the process tree, disrupting local system availability. This issue specifically impacts environments utilizing ProxyCommand functionality.",
    "acknowledgement": "Red Hat would like to thank Halil Oktay (oblivionsage) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55855",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libssh-0:0.12.0-3.el10_2"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42922",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libssh-main-0.12.1-4.hum1",
        "impact": "low"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59845\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59845"
    ],
    "name": "CVE-2026-59845",
    "mitigation": {
      "value": "To mitigate this issue, avoid using the ProxyCommand feature in libssh client configurations. This prevents the vulnerable code path from being exercised, thereby eliminating the risk of local denial of service due to unchecked fork() failures.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-21T13:02:11Z",
    "bugzilla": {
      "description": "libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification",
      "id": "2498180",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498180"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-253",
    "details": [
      "A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.",
      "A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection."
    ],
    "acknowledgement": "Red Hat would like to thank Ben Smyth for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55855",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libssh-0:0.12.0-3.el10_2"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42922",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libssh-main-0.12.1-4.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59847\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59847"
    ],
    "name": "CVE-2026-59847",
    "mitigation": {
      "value": "Disable the aes128-gcm@openssh.com and aes256-gcm@openssh.com ciphers.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-21T14:08:16Z",
    "bugzilla": {
      "description": "libssh: libssh: use-after-free via data callbacks on closed channels",
      "id": "2498183",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498183"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-416",
    "details": [
      "A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.",
      "A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions."
    ],
    "acknowledgement": "Red Hat would like to thank Zhou Qingyang for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55855",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libssh-0:0.12.0-3.el10_2"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42922",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libssh-main-0.12.1-4.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "libssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59850\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59850"
    ],
    "name": "CVE-2026-59850",
    "mitigation": {
      "value": "Manually verify the channel is not closed inside your channel data callbacks.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-09T22:39:01Z",
    "bugzilla": {
      "description": "vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion",
      "id": "2498867",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498867"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-94",
    "details": [
      "Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.",
      "A flaw was found in Vim, an open-source command-line text editor. The PHP omni-completion script improperly handles specially crafted input. When a victim opens a malicious PHP file and invokes omni-completion, an unescaped class or trait name can be interpreted as Ex commands. This allows a remote attacker to achieve arbitrary operating-system command execution."
    ],
    "statement": "Red Hat Product Security has rated this vulnerability as having a Moderate impact. While successful exploitation allows for arbitrary operating-system command execution when a user opens a crafted PHP file and triggers omni-completion, this feature is disabled by default in Red Hat products. The requirement for a non-default configuration, combined with mandatory user interaction, significantly reduces the real-world risk.\"",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48650",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "vim-2:9.1.083-9.el10_2.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55431",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47982",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47982",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.13"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54769",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202608130832-0"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-03T00:00:00Z",
        "advisory": "RHSA-2026:35387",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "vim-main-9.2.780-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1786435241"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1786533457"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1786533449"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1786435483"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1786533529"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59856\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59856\nhttps://github.com/vim/vim/commit/43afc581a37a35762dd0ef292f038b9dc5680a24\nhttps://github.com/vim/vim/security/advisories/GHSA-fh26-8f79-wj97"
    ],
    "name": "CVE-2026-59856",
    "mitigation": {
      "value": "Users should exercise caution when opening untrusted PHP files and avoid invoking omni-completion on them. To prevent exploitation, the PHP omni-completion script can be disabled by moving or renaming `phpcomplete.vim`. For example, execute `mv /usr/share/vim/vim*/autoload/phpcomplete.vim /usr/share/vim/vim*/autoload/phpcomplete.vim.bak`. This action will disable PHP omni-completion functionality. A restart of Vim is necessary for this change to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-09T22:34:54Z",
    "bugzilla": {
      "description": "vim: Vim: Denial of Service via out-of-bounds write in spell sound-folding",
      "id": "2498863",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498863"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-787",
    "details": [
      "Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] = NUL writes one byte past the end of the MAXWLEN-element stack buffer. A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor. This issue is fixed in version 9.2.0725.",
      "An out-of-bounds write vulnerability in Vim's spell_soundfold_sal() function allows an attacker to corrupt memory and crash the editor (Denial of Service) by supplying a specially crafted word during spell sound-folding."
    ],
    "statement": "This Moderate impact flaw in Vim's spell sound-folding feature can lead to a denial of service. A local attacker could provide a specially crafted word, causing an out-of-bounds write and crashing the editor. This vulnerability primarily affects interactive users of the Vim text editor.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-03T00:00:00Z",
        "advisory": "RHSA-2026:35387",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "vim-main-9.2.780-1.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59857\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59857\nhttps://github.com/vim/vim/commit/d22ff1c955ff87e8273210eae125aab0e85b6c30\nhttps://github.com/vim/vim/security/advisories/GHSA-m3hf-xcm3-xhm2"
    ],
    "name": "CVE-2026-59857",
    "mitigation": {
      "value": "This vulnerability can be mitigated by preventing Vim from automatically applying editor configurations embedded in files.\nAdd the following line to the global /etc/vimrc or local ~/.vimrc configuration file:\nset nomodeline",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-09T22:37:52Z",
    "bugzilla": {
      "description": "vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion",
      "id": "2498868",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498868"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-94",
    "details": [
      "Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.",
      "A command injection vulnerability in Vim's C omni-completion script allows an attacker to execute arbitrary commands if a user is tricked into opening a maliciously crafted tags file and manually invoking the autocomplete feature."
    ],
    "statement": "This Moderate flaw in Vim's C omni-completion script allows for arbitrary command execution. Exploitation requires a user to open a specially crafted C source file along with a malicious project tags file and then invoke C omni-completion. This limits the attack vector as it relies on specific user interaction and the presence of a hostile tags file, making it less likely to be exploited without user awareness.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48650",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "vim-2:9.1.083-9.el10_2.12"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55431",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "vim-2:9.1.083-5.el10_0.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48703",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-31.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48703",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "vim-2:8.0.1763-31.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47982",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47982",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "vim-2:8.2.2637-26.el9_8.13"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4.22",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:54769",
        "cpe": "cpe:/a:redhat:openshift:4.22::el9",
        "package": "rhcos-4.22.9.8.202608130832-0"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-03T00:00:00Z",
        "advisory": "RHSA-2026:35387",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "vim-main-9.2.780-1.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1786435241"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1786533457"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1786533449"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1786435483"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54387",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1786533529"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "vim",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59858\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59858\nhttps://github.com/vim/vim/commit/6b611b0d15603c52ebdad17172b0232b4f65704e\nhttps://github.com/vim/vim/security/advisories/GHSA-mf92-v4xw-j45x"
    ],
    "name": "CVE-2026-59858",
    "mitigation": {
      "value": "Users are advised to avoid opening untrusted C source files or project tags files in Vim. Exercising caution and only processing trusted content prevents exploitation.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-14T16:41:10Z",
    "bugzilla": {
      "description": "python-pyasn1: pyasn1: Denial of Service via crafted BER input",
      "id": "2500204",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500204"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.",
      "A flaw was found in pyasn1, a generic ASN.1 library for Python. The Basic Encoding Rules (BER) decoder, used by CER and DER codecs, processes long-form tags by accumulating continuation octets without an upper bound. A remote attacker can exploit this by providing a specially crafted input, leading to the construction of an arbitrarily large integer. This can cause the CPU cost to grow quadratically, resulting in a Denial of Service (DoS) for any application decoding untrusted BER, CER, or DER input."
    ],
    "statement": "A flaw was found in pyasn1's BER decoder. The decoder parses long-form tags by accumulating continuation octets without an upper bound, allowing crafted input to force construction of an arbitrarily large integer with quadratic CPU cost. On Python 3.11+, this can also trigger unhandled ValueError exceptions. Exploitation requires that an application passes untrusted BER, CER, or DER input directly to the pyasn1 decoder — pyasn1 is a library and does not independently accept network input. Many common uses of pyasn1 involve parsing trusted certificates or local configuration and are not exposed to this flaw. The realistic impact is a denial-of-service of the consuming Python process, with automatic recovery in typical service deployments.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:40236",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jaeger-main-2.19.0-1.1.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Fix deferred",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0",
        "impact": "moderate"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Fix deferred",
        "package_name": "lightspeed-core/lightspeed-stack-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core",
        "impact": "moderate"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Fix deferred",
        "package_name": "mta/mta-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8",
        "impact": "moderate"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Fix deferred",
        "package_name": "mta/mta-solution-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8",
        "impact": "moderate"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Fix deferred",
        "package_name": "rhmtc/openshift-migration-rhel8-operator",
        "cpe": "cpe:/a:redhat:rhmt:1",
        "impact": "moderate"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Fix deferred",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2",
        "impact": "moderate"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Fix deferred",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2",
        "impact": "moderate"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-agentic-sandbox-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed",
        "impact": "moderate"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed",
        "impact": "moderate"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Fix deferred",
        "package_name": "openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed",
        "impact": "moderate"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "rhacm2/volsync-operator-bundle",
        "cpe": "cpe:/a:redhat:acm:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Fix deferred",
        "package_name": "rhacm2/volsync-rhel9",
        "cpe": "cpe:/a:redhat:acm:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-operator-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-7-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:7",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-8-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Ceph Storage 9",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-9-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:9",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/o:redhat:enterprise_linux:10",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhel10/keylime-registrar",
        "cpe": "cpe:/o:redhat:enterprise_linux:10",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhel10/keylime-verifier",
        "cpe": "cpe:/o:redhat:enterprise_linux:10",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "resource-agents",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/keylime-registrar",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/keylime-verifier",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "mariadb11.8",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-trustme",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipelines-components-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-training-cuda128-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/a:redhat:openshift:4",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/a:redhat:openstack:16.2",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/a:redhat:openstack:17.1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso-operators/ee-openstack-ansible-ee-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Fix deferred",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/a:redhat:satellite:6",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Fix deferred",
        "package_name": "rhtas/model-transparency-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Fix deferred",
        "package_name": "rhtas/segment-reporting-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1",
        "impact": "moderate"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Fix deferred",
        "package_name": "stf/prometheus-webhook-snmp-rhel9",
        "cpe": "cpe:/a:redhat:stf:1.5",
        "impact": "moderate"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Fix deferred",
        "package_name": "stf/service-telemetry-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5",
        "impact": "moderate"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Fix deferred",
        "package_name": "stf/smart-gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5",
        "impact": "moderate"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59884\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59884\nhttps://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5\nhttps://github.com/pyasn1/pyasn1/releases/tag/v0.6.4\nhttps://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j"
    ],
    "name": "CVE-2026-59884",
    "mitigation": {
      "value": "Update to pyasn1 version 0.6.4 or later when available for your product stream. The impact is limited to availability (denial of service) — an attacker cannot access or modify data. Applications that do not process untrusted ASN.1/BER input are at reduced risk.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-14T16:40:00Z",
    "bugzilla": {
      "description": "pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER",
      "id": "2500380",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500380"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1050",
    "details": [
      "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.",
      "A flaw was found in pyasn1, a Python library for Abstract Syntax Notation One (ASN.1). The BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A remote attacker could exploit this by providing a specially crafted payload containing an OID with many arcs, leading to excessive CPU consumption and a denial of service (DoS) in applications that decode untrusted ASN.1 data. The corresponding encoders also exhibit this quadratic behavior when re-encoding attacker-supplied values."
    ],
    "statement": "A flaw was found in pyasn1. The BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call, allowing denial of service in applications that decode untrusted ASN.1 data (certificates, LDAP, SNMP, Kerberos). The corresponding encoders exhibit the same behavior when re-encoding attacker-supplied values. The arc-size limit introduced for CVE-2026-23490 does not mitigate this issue. This issue is fixed in pyasn1 version 0.6.4.",
    "affected_release": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50319",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "python3.12-pyasn1-0:0.6.4-1.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50319",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "python3.12-pyasn1-0:0.6.4-1.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50336",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "python3.12-pyasn1-0:0.6.4-1.el9ap"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:40236",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "jaeger-main-2.19.0-1.1.hum1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Migration Toolkit for Applications 8.2",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56347",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8.2::el9",
        "package": "mta/mta-rhel9-operator:1786481481"
      },
      {
        "product_name": "Red Hat Quay 3.1",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53520",
        "cpe": "cpe:/a:redhat:quay:3.10::el8",
        "package": "quay/quay-rhel8:1786395065"
      },
      {
        "product_name": "Red Hat Quay 3.12",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52968",
        "cpe": "cpe:/a:redhat:quay:3.12::el8",
        "package": "quay/quay-rhel8:1786170635"
      },
      {
        "product_name": "Red Hat Quay 3.15",
        "release_date": "2026-07-30T00:00:00Z",
        "advisory": "RHSA-2026:48933",
        "cpe": "cpe:/a:redhat:quay:3.15::el8",
        "package": "quay/quay-rhel8:1785261506"
      },
      {
        "product_name": "Red Hat Quay 3.9",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50931",
        "cpe": "cpe:/a:redhat:quay:3.9::el8",
        "package": "quay/quay-rhel8:1785950004"
      }
    ],
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Fix deferred",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Fix deferred",
        "package_name": "lightspeed-core/lightspeed-stack-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Affected",
        "package_name": "mta/mta-solution-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Fix deferred",
        "package_name": "rhmtc/openshift-migration-rhel8-operator",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Will not fix",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-agentic-sandbox-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Fix deferred",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Will not fix",
        "package_name": "rhacm2/volsync-operator-bundle",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Will not fix",
        "package_name": "rhacm2/volsync-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-operator-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-7-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-8-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 9",
        "fix_state": "Fix deferred",
        "package_name": "rhceph/rhceph-9-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhel10/keylime-registrar",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rhel10/keylime-verifier",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "resource-agents",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/keylime-registrar",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rhel9/keylime-verifier",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "llvm",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "mariadb11.8",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-trustme",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipelines-components-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-training-cuda128-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "rhoso-operators/ee-openstack-ansible-ee-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Fix deferred",
        "package_name": "rhtas/model-transparency-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Fix deferred",
        "package_name": "rhtas/segment-reporting-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Affected",
        "package_name": "stf/prometheus-webhook-snmp-rhel9",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Affected",
        "package_name": "stf/service-telemetry-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Affected",
        "package_name": "stf/smart-gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59885\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59885\nhttps://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9\nhttps://github.com/pyasn1/pyasn1/releases/tag/v0.6.4\nhttps://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj"
    ],
    "name": "CVE-2026-59885",
    "mitigation": {
      "value": "Update to pyasn1 version 0.6.4 or later when available for your product stream. The impact is limited to availability (denial of service) — an attacker cannot access or modify data. Applications that do not process untrusted ASN.1 input are at reduced risk.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-14T16:38:29Z",
    "bugzilla": {
      "description": "pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values",
      "id": "2500041",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500041"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.",
      "A remote attacker can exploit this by providing specially crafted BER/CER/DER-encoded ASN.1 data with a large exponent in the REAL value. When the application subsequently prints, logs, compares, or performs arithmetic on the decoded value, this can cause excessive CPU and memory consumption, leading to a denial of service (DoS)."
    ],
    "statement": "This flaw in pyasn1, rated as Important, could lead to a denial of service in Red Hat products that process untrusted ASN.1 data. A remote attacker could send a specially crafted BER, CER, or DER encoded REAL value with a large exponent, causing applications to consume excessive resources during decoding operations such as printing, logging, or arithmetic, thereby rendering the service unavailable.",
    "affected_release": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50319",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "python3.12-pyasn1-0:0.6.4-1.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59135",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "automation-controller-0:4.6.32-1.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50319",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "python3.12-pyasn1-0:0.6.4-1.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59135",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "automation-controller-0:4.6.32-1.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50336",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "python3.12-pyasn1-0:0.6.4-1.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59136",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "automation-controller-0:4.7.16-1.el9ap"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59243",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "python-pyasn1-0:0.6.2-1.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59238",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "python-pyasn1-0:0.6.2-1.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59329",
        "cpe": "cpe:/a:redhat:rhel_extras_sap_els:7",
        "package": "resource-agents-0:4.1.1-61.el7_9.24"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59329",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "package": "resource-agents-0:4.1.1-61.el7_9.24"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59240",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "python-pyasn1-0:0.1.9-7.el7_9.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53363",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "fence-agents-0:4.2.1-129.el8_10.29"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59241",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "python-pyasn1-0:0.3.7-6.el8_10.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53364",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::highavailability",
        "package": "resource-agents-0:4.9.0-54.el8_10.37"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58821",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "fence-agents-0:4.2.1-65.el8_4.32"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59248",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "python-pyasn1-0:0.3.7-6.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58820",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4::highavailability",
        "package": "resource-agents-0:4.1.1-90.el8_4.27"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58821",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "fence-agents-0:4.2.1-65.el8_4.32"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59248",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "python-pyasn1-0:0.3.7-6.el8_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58820",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4::highavailability",
        "package": "resource-agents-0:4.1.1-90.el8_4.27"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58835",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "fence-agents-0:4.2.1-89.el8_6.26"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59246",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "python-pyasn1-0:0.3.7-6.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58835",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "fence-agents-0:4.2.1-89.el8_6.26"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59246",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "python-pyasn1-0:0.3.7-6.el8_6.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58834",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6::highavailability",
        "package": "resource-agents-0:4.9.0-16.el8_6.24"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58822",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "fence-agents-0:4.2.1-112.el8_8.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59245",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "python-pyasn1-0:0.3.7-6.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58811",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8::highavailability",
        "package": "resource-agents-0:4.9.0-40.el8_8.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58822",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "fence-agents-0:4.2.1-112.el8_8.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59245",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "python-pyasn1-0:0.3.7-6.el8_8.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58811",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8::highavailability",
        "package": "resource-agents-0:4.9.0-40.el8_8.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53365",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "fence-agents-0:4.10.0-110.el9_8.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59242",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python-pyasn1-0:0.4.8-7.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58546",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "fence-agents-0:4.10.0-43.el9_2.25"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59239",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "python-pyasn1-0:0.4.8-6.el9_2.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58547",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "fence-agents-0:4.10.0-62.el9_4.29"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59244",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "python-pyasn1-0:0.4.8-6.el9_4.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58548",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "fence-agents-0:4.10.0-86.el9_6.21"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-25T00:00:00Z",
        "advisory": "RHSA-2026:59247",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "python-pyasn1-0:0.4.8-6.el9_6.2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59159",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "ansible-automation-platform-25/lightspeed-rhel8:1787229385"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50479",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-chatbot-rhel9:1785646188"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50479",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/lightspeed-rhel9:1785775360"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59155",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/eda-controller-rhel9:1787021043"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59155",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/gateway-rhel9:1787219751"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.7",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50340",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.7::el9",
        "package": "ansible-automation-platform-27/lightspeed-chatbot-rhel9:1785426734"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.7",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59153",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.7::el9",
        "package": "ansible-automation-platform-27/eda-controller-rhel9:1787163758"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.7",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59153",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.7::el9",
        "package": "ansible-automation-platform-27/ee-supported-rhel9:1787235693"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.7",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59153",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.7::el9",
        "package": "ansible-automation-platform-27/gateway-rhel9:1787218409"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.7",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59153",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.7::el9",
        "package": "ansible-automation-platform-27/lightspeed-rhel9:1787217531"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37094",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "mariadb11-8-main-11.8.8-3.hum1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Migration Toolkit for Applications 8.2",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56347",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8.2::el9",
        "package": "mta/mta-rhel9-operator:1786481481"
      },
      {
        "product_name": "Red Hat Quay 3.1",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53520",
        "cpe": "cpe:/a:redhat:quay:3.10::el8",
        "package": "quay/quay-rhel8:1786395065"
      },
      {
        "product_name": "Red Hat Quay 3.12",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:52968",
        "cpe": "cpe:/a:redhat:quay:3.12::el8",
        "package": "quay/quay-rhel8:1786170635"
      },
      {
        "product_name": "Red Hat Quay 3.15",
        "release_date": "2026-07-30T00:00:00Z",
        "advisory": "RHSA-2026:48933",
        "cpe": "cpe:/a:redhat:quay:3.15::el8",
        "package": "quay/quay-rhel8:1785261506"
      },
      {
        "product_name": "Red Hat Quay 3.9",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50931",
        "cpe": "cpe:/a:redhat:quay:3.9::el8",
        "package": "quay/quay-rhel8:1785950004"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.4",
        "release_date": "2026-08-05T00:00:00Z",
        "advisory": "RHSA-2026:50904",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.4::el9",
        "package": "rhtas/model-transparency-rhel9:1785420425"
      }
    ],
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Under investigation",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Affected",
        "package_name": "lightspeed-core/lightspeed-stack-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Affected",
        "package_name": "mta/mta-solution-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Containers",
        "fix_state": "Affected",
        "package_name": "rhmtc/openshift-migration-rhel8-operator",
        "cpe": "cpe:/a:redhat:rhmt:1"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Will not fix",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-agentic-sandbox-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Affected",
        "package_name": "openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Will not fix",
        "package_name": "rhacm2/volsync-operator-bundle",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2",
        "fix_state": "Will not fix",
        "package_name": "rhacm2/volsync-rhel9",
        "cpe": "cpe:/a:redhat:acm:2"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-24/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-24/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-24/platform-resource-runner-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-operator-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "python3.11-pyasn1",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "python3.11-pyasn1-modules",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "python3.12-pyasn1-modules",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "python3x-pyasn1",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Affected",
        "package_name": "rhceph/rhceph-7-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 8",
        "fix_state": "Affected",
        "package_name": "rhceph/rhceph-8-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:8"
      },
      {
        "product_name": "Red Hat Ceph Storage 9",
        "fix_state": "Affected",
        "package_name": "rhceph/rhceph-9-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "fence-agents",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "rhel10/keylime-registrar",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "rhel10/keylime-verifier",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "rhel9/keylime-registrar",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "rhel9/keylime-verifier",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "jaeger",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "llvm",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-trustme",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipelines-components-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-training-cuda128-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Under investigation",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Under investigation",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Under investigation",
        "package_name": "rhoso-operators/ee-openstack-ansible-ee-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Affected",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Under investigation",
        "package_name": "python3.12-pyasn1",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Under investigation",
        "package_name": "python3.12-pyasn1-modules",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Under investigation",
        "package_name": "python-pyasn1",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Under investigation",
        "package_name": "python-pyasn1-modules",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Under investigation",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Under investigation",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/segment-reporting-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Under investigation",
        "package_name": "stf/prometheus-webhook-snmp-rhel9",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Under investigation",
        "package_name": "stf/service-telemetry-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Under investigation",
        "package_name": "stf/smart-gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59886\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59886\nhttps://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886\nhttps://github.com/pyasn1/pyasn1/releases/tag/v0.6.4\nhttps://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r"
    ],
    "name": "CVE-2026-59886",
    "mitigation": {
      "value": "When processing untrusted ASN.1 data with pyasn1, avoid calling prettyPrint(), str(), float(), int(), or performing comparisons or arithmetic on decoded Real (ASN.1 REAL type) objects. Instead, inspect the raw (mantissa, base, exponent) tuple directly. Where logging decoded ASN.1 structures is necessary, filter out or sanitize Real-typed values before conversion.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-08T16:02:07Z",
    "bugzilla": {
      "description": "setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)",
      "id": "2498155",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498155"
    },
    "cvss3": {
      "cvss3_base_score": "6.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-1025",
    "details": [
      "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.",
      "A flaw was found in setuptools, a Python package management tool. The FileList component, responsible for handling file exclusions, did not properly normalize Unicode file names when applying exclusion rules. This oversight could allow a specially crafted file name, using a different Unicode normalization form (NFD) on macOS APFS or HFS+ file systems, to bypass an intended exclusion rule (NFC). As a result, sensitive files that should have been excluded could be inadvertently included in a source distribution, leading to information disclosure."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-10T00:00:00Z",
        "advisory": "RHSA-2026:37530",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python-setuptools-main-83.0.0-4.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Not affected",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Not affected",
        "package_name": "lightspeed-core/lightspeed-stack-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Not affected",
        "package_name": "lightspeed-core/rag-tool-cpu-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Not affected",
        "package_name": "lightspeed-core/rag-tool-cuda-12.9-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-solution-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-deep-inspection-rhel10",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-deep-inspection-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "migration-toolkit-virtualization/mtv-rhv-populator-rhel8",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Not affected",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Network Observability Operator",
        "fix_state": "Not affected",
        "package_name": "network-observability/network-observability-operator-bundle",
        "cpe": "cpe:/a:redhat:network_observ_optr:1"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/lightspeed-ocp-rag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaii/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaii/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaii/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaii/vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaii/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaii/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-24/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/ee-supported-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/ansible-builder-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/ee-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/mcp-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-operator-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/ansible-builder-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/de-minimal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/de-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/ee-supported-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/mcp-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-27/platform-resource-runner-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-tech-preview/ansible-devspaces-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat build of Quarkus Native builder",
        "fix_state": "Not affected",
        "package_name": "setuptools",
        "cpe": "cpe:/a:redhat:quarkus:3"
      },
      {
        "product_name": "Red Hat Ceph Storage 7",
        "fix_state": "Not affected",
        "package_name": "rhceph/rhceph-7-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:7"
      },
      {
        "product_name": "Red Hat Ceph Storage 9",
        "fix_state": "Not affected",
        "package_name": "rhceph/rhceph-9-rhel9",
        "cpe": "cpe:/a:redhat:ceph_storage:9"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Not affected",
        "package_name": "rhdh/rhdh-hub-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "python3.14-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rhel10-eus/rhel-10.0-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rhel10-eus/rhel-10.2-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rhel10/rhel-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rhel10/rteval",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rhel10/support-tools",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "fence-agents",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "rhel8-4-els/rhel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "ubi8/python-311",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "ubi8/python-312",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "ubi8/python-36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "ubi8/python-39",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "ubi8/toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python3.14-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9-2-els/rhel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9-8-els/rhel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9-eus/rhel-9.6-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9-eus/rhel-9.8-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9/keylime-registrar",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9/keylime-verifier",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9/python-311",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9/python-39",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rhel9/rhel-bootc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "ubi9/python-311",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "ubi9/python-312",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "ubi9/python-39",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "ubi9/toolbox",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "ubi9/ubi9",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "ubi9/ubi-stig",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "harfbuzz",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python3-mypy",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-cryptography",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "python-sentry-sdk",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "qt6-qtbase",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-automl-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-autorag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-caikit-nlp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-caikit-tgis-serving-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-guardrails-detector-huggingface-runtime-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-agent-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-autogluon-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-controller-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-router-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-llm-d-kv-cache-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-mlserver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipelines-components-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-ta-lmes-job-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-cuda121-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-cuda124-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-cuda128-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-cuda128-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-rocm62-torch24-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-rocm62-torch25-py311-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-rocm64-torch28-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-rocm64-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift4/dpdk-base-rhel8",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/devspaces-operator-bundle",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/udi-base-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/udi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/ocp-virt-validation-checkup-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat OpenShift Virtualization 4",
        "fix_state": "Not affected",
        "package_name": "container-native-virtualization/virt-launcher-rhel9",
        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-host-inventory-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-insights-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-puptoo-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-vmaas-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-vulnerability-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-yuptoo-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Not affected",
        "package_name": "rhtas/segment-reporting-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Self-service automation portal 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform/bootc-automation-portal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_portal:2"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Not affected",
        "package_name": "stf/prometheus-webhook-snmp-rhel9",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Not affected",
        "package_name": "stf/service-telemetry-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Not affected",
        "package_name": "stf/smart-gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59890\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59890\nhttps://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f\nhttps://github.com/pypa/setuptools/releases/tag/v83.0.0\nhttps://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c"
    ],
    "name": "CVE-2026-59890",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-17T17:41:36Z",
    "bugzilla": {
      "description": "sqlparse: sqlparse: Denial of Service via inefficient SQL parsing",
      "id": "2517523",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517523"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1333",
    "details": [
      "sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split(). This issue is fixed in version 0.6.0.",
      "A flaw was found in sqlparse, a Python module for parsing SQL. A remote attacker could exploit this vulnerability by providing specially crafted SQL input. This flaw causes inefficient processing of certain SQL patterns, leading to excessive CPU consumption and potentially a Denial of Service (DoS) condition, making the application unresponsive."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-08-31T00:00:00Z",
        "advisory": "RHSA-2026:61783",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1788205779"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-24/eda-controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-24/hub-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/ansible-dev-tools-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/eda-controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/gateway-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/hub-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/ansible-dev-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/ansible-dev-tools-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "python3.11-sqlparse",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "python3.12-sqlparse",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "python3x-sqlparse",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "python-sqlparse",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th-torch-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th-torch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th-torch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-training-cuda128-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ironic-rhel9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "python-sqlparse",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "python-sqlparse",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-aodh-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-aodh-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-aodh-evaluator",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-aodh-listener",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-aodh-notifier",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-barbican-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-barbican-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-barbican-keystone-listener",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-barbican-worker",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-ceilometer-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-ceilometer-central",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-ceilometer-compute",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-ceilometer-ipmi",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-ceilometer-notification",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-cinder-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-cinder-backup",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-cinder-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-cinder-scheduler",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-cinder-volume",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-designate-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-designate-backend-bind9",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-designate-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-designate-central",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-designate-mdns",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-designate-producer",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-designate-sink",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-designate-worker",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-ec2-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-glance-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-gnocchi-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-gnocchi-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-gnocchi-metricd",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-gnocchi-statsd",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-heat-all",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-heat-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-heat-api-cfn",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-heat-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-heat-engine",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-ironic-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-ironic-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-ironic-conductor",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-ironic-inspector",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-ironic-neutron-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-ironic-pxe",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-keystone",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-manila-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-manila-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-manila-scheduler",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-manila-share",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-mistral-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-mistral-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-mistral-engine",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-mistral-event-engine",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-mistral-executor",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-neutron-agent-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-neutron-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-neutron-dhcp-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-neutron-l3-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-neutron-metadata-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-neutron-metadata-agent-ovn",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-neutron-openvswitch-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-neutron-server",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-neutron-server-ovn",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-neutron-sriov-agent",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-nova-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-nova-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-nova-compute",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-nova-compute-ironic",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-nova-conductor",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-nova-libvirt",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-nova-novncproxy",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-nova-scheduler",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-octavia-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-octavia-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-octavia-health-manager",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-octavia-housekeeping",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-octavia-worker",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-panko-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-placement-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-tempest",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-tripleoclient",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Affected",
        "package_name": "rhosp-rhel8/openstack-zaqar-wsgi",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Affected",
        "package_name": "python-sqlparse",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "python-sqlparse",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-aodh-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-aodh-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-aodh-evaluator-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-aodh-listener-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-aodh-notifier-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-barbican-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-barbican-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-barbican-keystone-listener-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-barbican-worker-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-cinder-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-cinder-backup-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-cinder-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-cinder-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-cinder-volume-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-cloudkitty-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-cloudkitty-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-cloudkitty-processor-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-designate-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-designate-backend-bind9-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-designate-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-designate-central-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-designate-mdns-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-designate-producer-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-designate-sink-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-designate-worker-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-glance-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-heat-api-cfn-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-heat-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-heat-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-heat-engine-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-horizon-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-ironic-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-ironic-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-ironic-conductor-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-ironic-inspector-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-ironic-neutron-agent-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-ironic-pxe-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-keystone-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-manila-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-manila-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-manila-share-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-neutron-agent-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-neutron-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-neutron-dhcp-agent-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-neutron-metadata-agent-ovn-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-neutron-ovn-agent-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-neutron-server-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-neutron-sriov-agent-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-nova-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-nova-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-nova-compute-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-nova-conductor-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-nova-novncproxy-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-nova-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-octavia-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-octavia-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-octavia-health-manager-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-octavia-housekeeping-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-octavia-worker-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-ovn-bgp-agent-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-placement-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-tempest-all-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-watcher-api-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-watcher-applier-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-watcher-base-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Affected",
        "package_name": "rhoso/openstack-watcher-decision-engine-rhel9",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "python3.12-sqlparse",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "python-sqlparse",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Affected",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "tfm-pulpcore-python-sqlparse",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Update Infrastructure 4 for Cloud Providers",
        "fix_state": "Will not fix",
        "package_name": "python-sqlparse",
        "cpe": "cpe:/a:redhat:rhui:4::el8"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "fix_state": "Affected",
        "package_name": "rhui5/rhua-rhel9",
        "cpe": "cpe:/a:redhat:rhui:5::el9"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "fix_state": "Not affected",
        "package_name": "rhui5/rhua-tp-rhel9",
        "cpe": "cpe:/a:redhat:rhui:5::el9"
      },
      {
        "product_name": "Self-service automation portal 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform/bootc-automation-portal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_portal:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59893\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59893\nhttps://github.com/andialbrecht/sqlparse/commit/d1d80602741f77ec78e5a04ce4719244cf32352e\nhttps://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr"
    ],
    "name": "CVE-2026-59893",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "CVE-2026-59986 is a security vulnerability affecting the librabbitmq library. Specific details of the vulnerability have not been disclosed. librabbitmq is the C client library for RabbitMQ messaging middleware."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59986\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59986"
    ],
    "name": "CVE-2026-59986",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-08T00:04:49Z",
    "bugzilla": {
      "description": "openssh: OpenSSH: sftp client allows attacker to control downloaded file location",
      "id": "2497927",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497927"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-22",
    "details": [
      "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
      "A flaw was found in OpenSSH. The `sftp` client, when used to download files from a malicious server with the 'sftp server:/path .' command, does not properly restrict where those files are saved. This allows an attacker to control the download location, potentially overwriting existing files or placing malicious files in sensitive directories on the client system, which could compromise system integrity."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37382",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssh-main-10.4p1-1.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59995\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59995\nhttps://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2\nhttps://www.openssh.org/releasenotes.html#10.4p1\nhttps://www.openwall.com/lists/oss-security/2026/07/06/5"
    ],
    "name": "CVE-2026-59995",
    "mitigation": {
      "value": "To mitigate this issue, avoid using the `sftp server:/path .` command when connecting to untrusted or potentially malicious SFTP servers. Exercise caution and verify the authenticity of SFTP servers before initiating file transfers, especially when using commands that implicitly define the download destination, and also avoid running SFTP sessions with elevated privileges (such as root).",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-08T00:09:04Z",
    "bugzilla": {
      "description": "openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw",
      "id": "2497929",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497929"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-88",
    "details": [
      "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
      "A flaw was found in OpenSSH. The internal-sftp component within sshd incorrectly processes command-line arguments, recognizing only the first nine. This limitation can prevent the application of intended security configurations for SFTP (SSH File Transfer Protocol) connections, potentially leading to a bypass of security properties."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37382",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssh-main-10.4p1-1.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59997\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59997\nhttps://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2\nhttps://www.openssh.org/releasenotes.html#10.4p1\nhttps://www.openwall.com/lists/oss-security/2026/07/06/5"
    ],
    "name": "CVE-2026-59997",
    "mitigation": {
      "value": "To mitigate this issue, ensure that all security-relevant command-line arguments for the `internal-sftp` server are positioned within the first nine arguments. Alternatively, consider using the default SFTP server implementation if custom configurations relying on numerous arguments are not strictly necessary. If `internal-sftp` is used with more than nine arguments, verify that no critical security options are being silently discarded.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-08T00:13:08Z",
    "bugzilla": {
      "description": "openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options",
      "id": "2497942",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497942"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-358",
    "details": [
      "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
      "A flaw was found in `sshd`, the OpenSSH server daemon. When `DisableForwarding=yes` is configured to prevent network traffic forwarding, it incorrectly fails to take precedence over `PermitTunnel=yes`. This allows a remote attacker to bypass intended security restrictions and establish a tunnel, potentially leading to unauthorized network access or circumvention of security policies, even when forwarding is explicitly disabled."
    ],
    "statement": "This Moderate severity flaw in OpenSSH `sshd` allows `PermitTunnel=yes` to override `DisableForwarding=yes`, potentially bypassing intended security controls. In Red Hat environments where `DisableForwarding` is used to restrict SSH session capabilities, an attacker who compromises a user's session could still establish a tunnel, leading to unauthorized network access or data exfiltration. This bypass occurs even when administrators explicitly attempt to prevent forwarding, though `PermitTunnel` is not enabled by default.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37382",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "openssh-main-10.4p1-1.hum1",
        "impact": "moderate"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "openssh",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-59999\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59999\nhttps://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2\nhttps://www.openssh.org/releasenotes.html#10.4p1\nhttps://www.openwall.com/lists/oss-security/2026/07/06/5"
    ],
    "name": "CVE-2026-59999",
    "mitigation": {
      "value": "To mitigate this issue, if `DisableForwarding=yes` is set in `/etc/ssh/sshd_config` to prevent all forwarding, ensure that `PermitTunnel` is explicitly set to `no` in the same configuration file. This will enforce the intended security policy.\nAfter modifying `/etc/ssh/sshd_config`, restart the `sshd` service for the changes to take effect. This may temporarily interrupt active SSH sessions.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-15T15:04:21Z",
    "bugzilla": {
      "description": "nginx: NGINX: Memory disclosure and denial of service in ngx_http_slice_module",
      "id": "2500992",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500992"
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-824",
    "details": [
      "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart.\nImpact:\nThis vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.\nNote: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter.\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A vulnerability in the NGINX ngx_http_slice_module allows remote, unauthenticated attackers to access uninitialized memory via crafted requests. If configured with unnamed regex captures or background cache updates, this flaw can result in limited memory disclosure or a denial-of-service crash."
    ],
    "statement": "Important: This vulnerability in NGINX's `ngx_http_slice_module` could lead to memory disclosure or denial of service. The impact on Red Hat products is reduced because the `ngx_http_slice_module` is not enabled by default. Exploitation requires explicit configuration of the module with the `slice` directive and unnamed regex captures, or during a background cache update, limiting exposure in typical deployments.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59220",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "nginx-2:1.26.3-6.el10_2.6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59216",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nginx:1.24-8100020260809162034.489197e6"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-26T00:00:00Z",
        "advisory": "RHSA-2026:46012",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nginx-main-1.30.4-2.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "nginx:1.24/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "nginx:1.26/nginx",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Lightspeed proxy 1",
        "fix_state": "Affected",
        "package_name": "insights-proxy/insights-proxy-container-rhel9",
        "cpe": "cpe:/a:redhat:insights_proxy:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-60005\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-60005\nhttps://my.f5.com/manage/s/article/K000162100"
    ],
    "name": "CVE-2026-60005",
    "mitigation": {
      "value": "To mitigate this issue, disable the ngx_http_slice_module entirely if it is not required.\nIf the module must be used, avoid unnamed regex captures with the slice directive and explicitly disable proxy_cache_background_update.\nReload or restart the NGINX service to apply these changes. Please note this may cause a brief service interruption.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-30T13:42:03Z",
    "bugzilla": {
      "description": "Date-Manip: Date::Manip: Incorrect date parsing leads to logic errors",
      "id": "2509488",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509488"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-681",
    "details": [
      "Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check.\nThe parse regexes capture year, month and day with the `\\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\\p{Nd}` and not just `[0-9]`. Date::Manip::Base::check then validates the captured fields with numeric comparisons alone (`$y<1 || $y>9999`, `$m<1 || $m>12`, `$d<1 || $d>$days`), and _parse_check stores the numified fields (`$y+0`). Perl truncates a string at the first character that is not an ASCII digit, so a field whose leading characters are ASCII digits numifies to an in-range prefix and satisfies every test: a year field of three ASCII digits followed by U+0664 ARABIC-INDIC DIGIT FOUR numifies to 202, giving the year 0202, and one non-ASCII digit in the month or day field shifts those fields the same way. The hour, minute and second fields match explicit ASCII character classes (`0?[0-9]`, `[0-5][0-9]`) and do not shift, though a non-ASCII digit in a fractional hour or minute field truncates the fraction.\nAny caller that passes an untrusted character string to ParseDate() or Date::Manip::Date->parse() can get back a date that differs from the string it parsed, with no parse error. Where the parsed date gates logic such as an expiry check or a retention window, the shift goes unnoticed.",
      "A flaw was found in Date::Manip. This vulnerability allows an attacker to provide specially crafted input containing non-ASCII decimal digits to the Date::Manip library for Perl. The library's parsing logic incorrectly processes these digits, truncating the input and resulting in an inaccurate date being returned without any error indication. This can lead to critical logic errors in applications that depend on precise date parsing, potentially affecting functions like expiry checks or data retention policies."
    ],
    "statement": "Red Hat ships the perl-Date-Manip package across RHEL 6 through 10 and RHIVOS. All shipped versions (6.24 through 6.94) are within the affected range. Exploitation requires untrusted input containing non-ASCII Unicode decimal digits to be passed to the Date::Manip parsing functions, limiting practical impact to applications processing internationalized date strings.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "perl-Date-Manip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "perl-Date-Manip",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "perl-Date-Manip",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "perl-Date-Manip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "perl-Date-Manip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-60074\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-60074\nhttps://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Base.pm#L602-614\nhttps://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Date.pm#L1536-1539\nhttps://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60074-r1.patch"
    ],
    "name": "CVE-2026-60074",
    "mitigation": {
      "value": "Ensure that date input passed to Date::Manip parsing functions is validated to contain only ASCII digits (0-9) before processing.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-30T13:42:17Z",
    "bugzilla": {
      "description": "perl-Date-Manip: Date::Manip for Perl: Denial of Service via CPU exhaustion in date parsing",
      "id": "2509486",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509486"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1333",
    "details": [
      "Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time.\n_parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached through a leading `(?:$atrx|^|\\s+)`. The engine therefore retries the match at every position of an interior whitespace run: at each start position the leading `\\s+` consumes the rest of the run greedily, the time alternation fails because the run holds no digits, and the engine backtracks a space at a time across the run before advancing the start position, which is quadratic in the length of the run. No time need be present in the string for this to happen, only a long run of whitespace, and the parse time rises about fourfold for each doubling of the run: a few kilobytes of whitespace costs seconds of CPU per parse and tens of kilobytes costs minutes.\nAny caller that passes an untrusted string of unbounded length to ParseDate(), Date::Manip::Date->parse() or ->parse_time() can be made to spend unbounded CPU in a single parse, a denial of service.",
      "A flaw was found in Date::Manip for Perl. An attacker could exploit a vulnerability in the `_parse_time` function by providing a specially crafted input string containing long sequences of whitespace. This could lead to excessive CPU consumption due to inefficient processing, resulting in a Denial of Service (DoS) for the affected system."
    ],
    "statement": "The `perl-Date-Manip` module is vulnerable to a denial of service. Applications that process untrusted, unbounded input strings containing long sequences of whitespace can experience significant CPU exhaustion, leading to service unavailability. This is due to quadratic backtracking during date parsing.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56971",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "perl-Date-Manip-0:6.94-5.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57562",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "perl-Date-Manip-0:6.60-3.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56970",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "perl-Date-Manip-0:6.85-3.el9_8.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "perl-Date-Manip",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "perl-Date-Manip",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-60075\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-60075\nhttps://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Date.pm#L1526\nhttps://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Date.pm#L1811\nhttps://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60075-r1.patch"
    ],
    "name": "CVE-2026-60075",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-14T15:34:35Z",
    "bugzilla": {
      "description": "DBI: DBI::ProfileData: Denial of Service due to unbounded path index",
      "id": "2500005",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500005"
    },
    "cvss3": {
      "cvss3_base_score": "2.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-770",
    "details": [
      "DBI::ProfileData versions before 1.651 for Perl do not limit the path index.\nThe path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.",
      "A flaw was found in DBI::ProfileData, a Perl module. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a specially crafted input. The flaw exists because the software does not properly limit the path index when processing profile dump files, which can lead to excessive memory consumption."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "perl-DBI:1.641/perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-60081\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-60081\nhttps://github.com/perl5-dbi/dbi/commit/6764e755e83ee1ebb1b40760e5b53eb50960bd7a.patch\nhttps://github.com/perl5-dbi/dbi/security/advisories/GHSA-ww49-w4mv-jrr4\nhttps://metacpan.org/release/HMBRAND/DBI-1.651/changes"
    ],
    "name": "CVE-2026-60081",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-14T15:35:00Z",
    "bugzilla": {
      "description": "perl-DBI: perl-DBI: Denial of Service via out-of-bounds read",
      "id": "2500019",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500019"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.\nWhen the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index.\nThis could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.",
      "A flaw was found in perl-DBI, a database interface for Perl. This vulnerability arises when the DBI library processes inconsistent data, specifically when a statement handle lacks fields but is associated with a non-empty data row. This inconsistency can cause the internal row-buffer to attempt reading from an invalid memory location, an out-of-bounds read. An attacker could exploit this by supplying malformed metadata and rows to the `prepare` method, potentially leading to application instability or a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "perl-DBI:1.641/perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-60082\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-60082\nhttps://github.com/perl5-dbi/dbi/commit/397868704291bbf0989b97e2c0661189890653e2.patch\nhttps://github.com/perl5-dbi/dbi/security/advisories/GHSA-rwhc-hhmv-cjvg\nhttps://metacpan.org/release/HMBRAND/DBI-1.651/changes"
    ],
    "name": "CVE-2026-60082",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "CVE-2026-61547 is a security vulnerability in librabbitmq (RabbitMQ C client library). Details of the vulnerability have not been disclosed yet, and all versions are affected."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-61547\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-61547"
    ],
    "name": "CVE-2026-61547",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-13T16:45:11Z",
    "bugzilla": {
      "description": "uclouvain/openjpeg: OpenJPEG: Denial of Service via integer overflow in opj_pi_initialise_encode",
      "id": "2457931",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457931"
    },
    "cvss3": {
      "cvss3_base_score": "3.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-190",
    "details": [
      "A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.",
      "A flaw was found in uclouvain openjpeg. A local attacker can exploit an integer overflow vulnerability within the `opj_pi_initialise_encode` function. This manipulation can lead to a Denial of Service (DoS), making the affected system or application unavailable."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "openjpeg2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "openjpeg2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "openjpeg2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "openjpeg2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6192\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6192\nhttps://github.com/uclouvain/openjpeg/\nhttps://github.com/uclouvain/openjpeg/commit/839936aa33eb8899bbbd80fda02796bb65068951\nhttps://github.com/uclouvain/openjpeg/issues/1619\nhttps://github.com/uclouvain/openjpeg/pull/1628\nhttps://vuldb.com/submit/797385\nhttps://vuldb.com/vuln/357114\nhttps://vuldb.com/vuln/357114/cti"
    ],
    "name": "CVE-2026-6192",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-30T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "status": ""
    },
    "cwe": "",
    "details": [
      "The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass validation and be processed incorrectly. The issue may affect applications that rely on these functions to validate untrusted BSON data before further processing. This issue affects MongoDB C Driver versions prior to 1.30.5, MongoDB C Driver version 2.0.0 and MongoDB C Driver version 2.0.1."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6231\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6231"
    ],
    "name": "CVE-2026-6231",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-29T23:57:51Z",
    "bugzilla": {
      "description": "ImageMagick: ImageMagick: Denial of Service via heap buffer over-write in morphology operation with invalid kernel",
      "id": "2508793",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508793"
    },
    "cvss3": {
      "cvss3_base_score": "4.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-805",
    "details": [
      "ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.",
      "A flaw was found in ImageMagick, a widely used software for editing and manipulating digital images. A local user could provide a specially crafted, invalid kernel during a morphology operation. This action could trigger a heap buffer over-write, leading to a denial of service (DoS) for the ImageMagick application. This vulnerability primarily impacts the availability of the image processing service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "ImageMagick",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-62343\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-62343\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f5m7-cqgw-8hm7"
    ],
    "name": "CVE-2026-62343",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-28T16:43:08Z",
    "bugzilla": {
      "description": "glibc: glibc: Application crash or uninitialized memory read via crafted DNS response",
      "id": "2463539",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2463539"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1284",
    "details": [
      "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
      "A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42694",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "glibc-0:2.39-128.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42733",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "glibc-0:2.28-251.el8_10.40"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42733",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "glibc-0:2.28-251.el8_10.40"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:42952",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "glibc-0:2.34-274.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:42952",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "glibc-0:2.34-274.el9_8"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46836",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1784821670"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-01T00:00:00Z",
        "advisory": "RHSA-2026:12740",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "glibc-main-2.42-12.hum1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-gateway-opa-rhel9:1784775772"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-gateway-rhel9:1784775770"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-jaeger-query-rhel9:1784775834"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-operator-bundle:1784777166"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-query-rhel9:1784775793"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-rhel9:1784775768"
      },
      {
        "product_name": "Red Hat OpenShift distributed tracing 3.10.1",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44624",
        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
        "package": "rhosdt/tempo-rhel9-operator:1784775782"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1784794818"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1784794778"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1784795112"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1784794289"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1784795076"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "compat-glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "compat-glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6238\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6238\nhttps://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u\nhttps://sourceware.org/bugzilla/show_bug.cgi?id=34069"
    ],
    "name": "CVE-2026-6238",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-29T00:00:00Z",
    "bugzilla": {
      "description": "curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies",
      "id": "2461202",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461202"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-201",
    "details": [
      "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\nThis can happen when the following conditions are true:\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\na redirect to a URL using another scheme (say `https://`), accessed using a\nsecond, different, proxy",
      "A flaw was found in curl. When curl is configured to use distinct proxies for different URL schemes, a redirect from a URL using an authenticated proxy to one using an unauthenticated proxy can inadvertently expose the initial proxy's credentials. This improper credential management (CWE-522) may allow an attacker to gain unauthorized access or information by intercepting these disclosed credentials."
    ],
    "statement": "Moderate: This flaw in curl and libcurl allows proxy credentials to be inadvertently exposed to a second proxy during a redirect. This issue arises when curl is configured to use distinct proxies for different URL schemes, the initial proxy requires authentication, and a subsequent proxy does not. Red Hat products utilizing curl or libcurl in such a specific proxy chaining configuration may be affected.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:12916",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.20.0-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Fix deferred",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6253\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6253\nhttps://curl.se/docs/CVE-2026-6253.html"
    ],
    "name": "CVE-2026-6253",
    "mitigation": {
      "value": "To mitigate this issue, avoid configuring curl or libcurl to use proxies that require credentials. This prevents the scenario where credentials for a first proxy could be inadvertently passed to a second proxy during a redirect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-29T00:00:00Z",
    "bugzilla": {
      "description": "curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers",
      "id": "2461203",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461203"
    },
    "cvss3": {
      "cvss3_base_score": "3.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-346",
    "details": [
      "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
      "A flaw was found in libcurl. This vulnerability allows for information disclosure when a custom `Host:` header is used in an initial HTTP request, and a subsequent request reuses the same connection without specifying a new `Host:` header. This can lead to libcurl incorrectly sending cookies intended for the first host to the second host, resulting in a cookie leak. This issue is categorized as an Origin Validation Error (CWE-346). Exploitation typically requires specific debugging configurations."
    ],
    "statement": "This Low severity flaw affects libcurl when a custom `Host:` header is initially set for an HTTP request, and a subsequent request uses the same easy handle without a custom `Host:` header. This can lead to the second request sending cookies intended for the first host. The `curl` command-line tool is not affected by this issue. Exploitation typically requires specific debugging configurations, reducing its overall impact.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:12916",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.20.0-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Fix deferred",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6276\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6276\nhttps://curl.se/docs/CVE-2026-6276.html"
    ],
    "name": "CVE-2026-6276",
    "mitigation": {
      "value": "To mitigate this issue, avoid using custom `Host:` headers with libcurl, especially when reusing the same easy handle for multiple requests. This vulnerability primarily arises from specific debugging configurations.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-03T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect pr_fsio_stat() to system() via a crafted RENAME request."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63090\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63090"
    ],
    "name": "CVE-2026-63090",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-03T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which results in a negative off_t value. Attackers can exploit the subsequent conversion to uint32_t, causing an approximately 4 GB requested read length and forcing the server to read beyond the end of the SSH channel data and write overread process memory into the uploaded file. In tested configurations, the disclosed data contains libc, libcrypto, and PIE pointers sufficient to derive their randomized base addresses, thereby bypassing ASLR and enabling reliable exploitation of memory corruption vulnerabilities in the same process."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63091\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63091"
    ],
    "name": "CVE-2026-63091",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-01-27T00:00:00Z",
    "bugzilla": {
      "description": "libsoup: libsoup: HTTP Request Smuggling via Unsigned to Signed Conversion Error",
      "id": "2458479",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458479"
    },
    "cvss3": {
      "cvss3_base_score": "4.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-444",
    "details": [
      "A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` function by sending a malicious HTTP request. This vulnerability occurs when libsoup operates behind a non-libsoup proxy server or as a proxy in front of a non-libsoup backend server. Successful exploitation can allow an attacker to bypass security controls, poison web caches, or gain unauthorized access.",
      "A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` function by sending a malicious HTTP request. This vulnerability occurs when libsoup operates behind a non-libsoup proxy server or as a proxy in front of a non-libsoup backend server. Successful exploitation can allow an attacker to bypass security controls, poison web caches, or gain unauthorized access."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Under investigation",
        "package_name": "libsoup3",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Under investigation",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Under investigation",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Under investigation",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Under investigation",
        "package_name": "libsoup",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6324\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6324\nhttps://gitlab.gnome.org/GNOME/libsoup/-/issues/508"
    ],
    "name": "CVE-2026-6324",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "The updated packages fix some security vulnerabilities. libevent is a lightweight event notification library used for handling event loops and callback mechanisms, widely used in network applications."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63379\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63379"
    ],
    "name": "CVE-2026-63379",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "The updated packages fix some security vulnerabilities affecting the libevent library."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63381\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63381"
    ],
    "name": "CVE-2026-63381",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "The updated packages fix some security vulnerabilities."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63382\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63382"
    ],
    "name": "CVE-2026-63382",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "The updated packages fix some security vulnerabilities."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63383\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63383"
    ],
    "name": "CVE-2026-63383",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "The updated packages fix some security vulnerabilities."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63384\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63384"
    ],
    "name": "CVE-2026-63384",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "The updated packages fix some security vulnerabilities."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63385\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63385"
    ],
    "name": "CVE-2026-63385",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "The updated packages fix some security vulnerabilities."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63387\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63387"
    ],
    "name": "CVE-2026-63387",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "The updated packages fix some security vulnerabilities."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63388\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63388"
    ],
    "name": "CVE-2026-63388",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-11T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
      "status": ""
    },
    "cwe": "",
    "details": [
      "The MPG WordPress plugin prior to 4.1.8 does not sanitize and escape parameters before reflecting them back into the response, allowing an unauthenticated attacker to perform reflected cross-site scripting against a victim who is induced to send a crafted request."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63676\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63676"
    ],
    "name": "CVE-2026-63676",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-10T18:40:11Z",
    "bugzilla": {
      "description": "glibc: glibc: Process abort due to invalid memory in wordexp",
      "id": "2513608",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513608"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1341",
    "details": [
      "Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.",
      "A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS)."
    ],
    "statement": "This flaw in glibc has Moderate impact, as it can lead to a denial of service. Exploitation requires an application to specifically call `wordexp` with the `WRDE_APPEND` flag, followed by a `wordfree` call, which can result in a process abort. This vulnerability affects applications that utilize this particular programming pattern.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:53069",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "glibc-main-2.43-8.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "compat-glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "compat-glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "filesystem",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6368\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6368\nhttps://sourceware.org/bugzilla/show_bug.cgi?id=34090\nhttps://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"
    ],
    "name": "CVE-2026-6368",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-21T01:35:41Z",
    "bugzilla": {
      "description": "texlive: evince: TeX Live SyncTeX Parser: Heap use-after-free allows arbitrary code execution via malformed file",
      "id": "2503120",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503120"
    },
    "cvss3": {
      "cvss3_base_score": "6.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.",
      "A flaw was found in the SyncTeX parser, part of TeX Live and used by applications like GNOME Evince. A remote attacker could exploit a heap use-after-free vulnerability by providing a specially crafted SyncTeX file (e.g., .synctex or .synctex.gz). This could lead to application crashes or, in severe cases, allow the attacker to execute arbitrary code on the affected system."
    ],
    "statement": "The SyncTeX parser shipped with TeX Live and embedded by GNOME Evince in Red Hat Enterprise Linux is affected by this vulnerability. A heap use-after-free in synctex_parser.c can be triggered by opening a specially crafted .synctex file, potentially leading to application crashes or code execution. All shipped versions of TeX Live (pre-2026) and evince are within the affected range.",
    "acknowledgement": "Red Hat would like to thank Fatih Çelik for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "texlive",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "evince",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "texlive",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "evince",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "texlive",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "evince",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "texlive",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "evince",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "texlive",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63729\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63729\nhttps://fatihhcelik.github.io/posts/evince-synctex-heap-use-after-free/\nhttps://github.com/TeX-Live/texlive-source/\nhttps://github.com/TeX-Live/texlive-source/commit/002dcd3eac30db5c352f53d4181737961cc7ee9a\nhttps://www.vulncheck.com/advisories/tex-live-synctex-parser-heap-use-after-free-via-malformed-synctex-file"
    ],
    "name": "CVE-2026-63729",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-19T00:00:00Z",
    "bugzilla": {
      "description": "kernel: RDMA/core: Prefer NLA_NUL_STRING",
      "id": "2502309",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502309"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nRDMA/core: Prefer NLA_NUL_STRING\nThese attributes are evaluated as c-string (passed to strcmp), but\nNLA_STRING doesn't check for the presence of a \\0 terminator.\nEither this needs to switch to nla_strcmp() and needs to adjust printf fmt\nspecifier to not use plain %s, or this needs to use NLA_NUL_STRING.\nAs the code has been this way for long time, it seems to me that userspace\ndoes include the terminating nul, even tough its not enforced so far, and\nthus NLA_NUL_STRING use is the simpler solution.",
      "A flaw was found in the Linux kernel's RDMA/core component. This vulnerability arises from the improper handling of Netlink Attribute (NLA) strings, where attributes evaluated as C-strings do not properly check for a null terminator. A local attacker could potentially provide specially crafted input, leading to unexpected behavior or information disclosure due to out-of-bounds reads during string comparisons."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63860\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63860\nhttps://lore.kernel.org/linux-cve-announce/2026071933-CVE-2026-63860-6168@gregkh/T"
    ],
    "name": "CVE-2026-63860",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-19T00:00:00Z",
    "bugzilla": {
      "description": "kernel: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf",
      "id": "2502447",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502447"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nscsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf\niscsi_encode_text_output() concatenates \"key=value\\0\" records into\nlogin->rsp_buf, an 8192-byte kzalloc(MAX_KEY_VALUE_PAIRS) buffer\nallocated in iscsit_alloc_login_setup_buffer(). The three sprintf() call\nsites in this function (lines 1398, 1411, 1424 in v7.1-rc2) never check\nthe remaining buffer capacity:\n*length += sprintf(output_buf, \"%s=%s\", er->key, er->value);\n*length += 1;\noutput_buf = textbuf + *length;\nThe 8192-byte ceiling at iscsi_target_check_login_request() bounds the\n*input* Login PDU payload, but a single PDU can carry up to 2048 minimal\nfour-byte \"a=b\\0\" pairs, each unknown key expanding to a 16-byte\n\"a=NotUnderstood\\0\" output record via iscsi_add_notunderstood_response().\n2048 * 16 = 32 KiB of output into an 8 KiB buffer, producing a ~24 KiB\nheap overrun in the kmalloc-8k slab.\nThe fix introduces a static iscsi_encode_text_record() helper that uses\nsnprintf() with a per-call bounds check against the remaining buffer,\nand threads a u32 textbuf_size parameter through\niscsi_encode_text_output(). Both call sites in\niscsi_target_handle_csg_zero() (PHASE_SECURITY) and\niscsi_target_handle_csg_one() (PHASE_OPERATIONAL) pass\nMAX_KEY_VALUE_PAIRS. On overflow the encoder logs the condition, calls\niscsi_release_extra_responses() to drop queued records, and returns -1;\nboth caller sites now emit ISCSI_STATUS_CLS_INITIATOR_ERR /\nISCSI_LOGIN_STATUS_INIT_ERR via iscsit_tx_login_rsp() before returning,\nso the initiator sees an explicit failed-login response rather than a\nsilent connection drop. (Prior to this patch only the PHASE_OPERATIONAL\ncaller did that; the PHASE_SECURITY caller is converted to the same\nshape.)",
      "A flaw was found in the Linux kernel's iSCSI (Internet Small Computer System Interface) target functionality. This vulnerability, a heap overrun, occurs because the iscsi_encode_text_output() function does not properly check buffer capacity when processing login requests. A remote attacker could exploit this by sending a specially crafted login request with numerous key-value pairs, leading to a memory corruption issue and potentially a denial of service (DoS) on the system."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-12T00:00:00Z",
        "advisory": "RHSA-2026:54343",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "kernel-0:6.12.0-211.47.1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57254",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::nfv",
        "package": "kernel-rt-0:4.18.0-553.157.1.rt7.498.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57253",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "kernel-0:4.18.0-553.157.1.el8_10"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63887\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63887\nhttps://lore.kernel.org/linux-cve-announce/2026071940-CVE-2026-63887-cf4b@gregkh/T"
    ],
    "name": "CVE-2026-63887",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-19T00:00:00Z",
    "bugzilla": {
      "description": "kernel: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()",
      "id": "2502443",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502443"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nscsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()\nTwo latent bugs in the Text-phase handler, both present since the\noriginal LIO integration in commit e48354ce078c (\"iscsi-target: Add\niSCSI fabric support for target v4.1\"):\n1) DataDigest CRC buffer overread (4 bytes past text_in).\ntext_in is kzalloc()'d at ALIGN(payload_length, 4).  rx_size is then\nincremented by ISCSI_CRC_LEN to make room for the received DataDigest\nin the iovec, but the same (now-bumped) rx_size is passed as the\nbuffer length to iscsit_crc_buf():\nif (conn->conn_ops->DataDigest) {\n...\nrx_size += ISCSI_CRC_LEN;\n}\n...\nif (conn->conn_ops->DataDigest) {\ndata_crc = iscsit_crc_buf(text_in, rx_size, 0, NULL);\niscsit_crc_buf() walks rx_size bytes of text_in with crc32c(), so\nwhen DataDigest is negotiated it reads 4 bytes past the end of the\ntext_in allocation.  KASAN reproduces this directly on the unpatched\nmainline tree as slab-out-of-bounds in crc32c() called from the Text\nPDU path.  The OOB bytes feed crc32c() and are then compared against\nthe initiator-supplied checksum, so the value does not flow back to\nthe attacker, but the kernel does read past the buffer on every Text\nPDU with DataDigest=CRC32C.\nFix by passing the actual padded payload length\n(ALIGN(payload_length, 4)) that was used for the kzalloc().\n2) Stale cmd->text_in_ptr re-free (double-free) on ERL>0 bad DataDigest\ndrop.\nOn DataDigest mismatch with ErrorRecoveryLevel > 0 the handler\nsilently drops the PDU and lets the initiator plug the CmdSN gap:\nkfree(text_in);\nreturn 0;\ncmd->text_in_ptr still points at the freed buffer.  The next Text\nRequest on the same ITT re-enters iscsit_setup_text_cmd(), which\nunconditionally does\nkfree(cmd->text_in_ptr);\ncmd->text_in_ptr = NULL;\nfreeing the same pointer a second time.  Session teardown via\niscsit_release_cmd() has the same shape and hits the same double-free\nif the connection is dropped before a second Text Request arrives.\nOn an unmodified mainline tree the bug-1 CRC overread fires first on\nthe initial valid Text Request and perturbs the subsequent state, so\n#4 was isolated by building a kernel with only the bug-1 hunk of this\npatch applied plus temporary printk() observability around the three\nrelevant kfree() sites.  The observability prints are not part of\nthis patch.  On that build, a three-PDU Text Request sequence after\nlogin produces two back-to-back splats:\nBUG: KASAN: double-free in iscsit_setup_text_cmd+0x??\nBUG: KASAN: double-free in iscsit_release_cmd+0x??\nshowing the same pointer freed in the ERL>0 drop path and again in\niscsit_setup_text_cmd() (next Text Request on the same ITT) and once\nmore in iscsit_release_cmd() (session teardown).  On distro kernels\nwith CONFIG_SLAB_FREELIST_HARDENED=y (default) the double-free\nbecomes a remote kernel BUG(); on non-hardened kernels it corrupts\nthe slab freelist.\nFix by clearing cmd->text_in_ptr after the kfree() in the ERL>0 drop\npath.  With both hunks applied #4 is directly observable on the stock\ntree without observability printks; fixing bug-1 alone would mask #4\nless, not more, so the hunks are submitted together.\nBoth fixes are one-liners.  The Text PDU state machine is unchanged and\nthe wire protocol is unaffected.",
      "A flaw was found in the Linux kernel's iSCSI (Internet Small Computer System Interface) target subsystem. This vulnerability involves a buffer overread and a double-free error when processing iSCSI Text commands. A remote attacker could exploit these issues by sending specially crafted network packets, leading to a kernel crash or memory corruption. This could result in a Denial of Service (DoS) for the affected system."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57251",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "kernel-0:6.12.0-211.49.1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57254",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::nfv",
        "package": "kernel-rt-0:4.18.0-553.157.1.rt7.498.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57253",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "kernel-0:4.18.0-553.157.1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57252",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "kernel-0:5.14.0-687.41.1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57252",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "kernel-0:5.14.0-687.41.1.el9_8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63888\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63888\nhttps://lore.kernel.org/linux-cve-announce/2026071940-CVE-2026-63888-a5d6@gregkh/T"
    ],
    "name": "CVE-2026-63888",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-19T00:00:00Z",
    "bugzilla": {
      "description": "kernel: USB: serial: omninet: fix memory corruption with small endpoint",
      "id": "2502472",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502472"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nUSB: serial: omninet: fix memory corruption with small endpoint\nMake sure that the bulk-out buffers are at least as large as the\nhardcoded transfer size to avoid user-controlled slab corruption should\na malicious device report a smaller endpoint max packet size than\nexpected.",
      "A flaw was found in the Linux kernel's USB serial omninet driver. A malicious Universal Serial Bus (USB) device could exploit this by reporting a smaller maximum packet size than anticipated. This action would cause the system to allocate undersized data buffers, leading to memory corruption. Such corruption could allow an attacker to trigger a denial of service or potentially execute unauthorized code."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-63928\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-63928\nhttps://lore.kernel.org/linux-cve-announce/2026071949-CVE-2026-63928-7715@gregkh/T"
    ],
    "name": "CVE-2026-63928",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-19T00:00:00Z",
    "bugzilla": {
      "description": "kernel: security/keys: fix missed RCU read section on lookup",
      "id": "2502380",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502380"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nsecurity/keys: fix missed RCU read section on lookup\nNicholas Carlini reports that the keyring code calls assoc_array_find()\nin find_key_to_update() without holding the RCU read lock, while the\nassoc_array_gc() code really is designed around removing the node from\nthe tree and then freeing it after an RCU grace-period.\nThe regular key handling doesn't see this because holding the keyring\nsemaphore hides any lifetime issues, but the persistent key handling\nuses a different model.\nInstead of extending the keyring locking, just do the simple RCU locking\nthat the assoc_array was designed for.",
      "A flaw was found in the Linux kernel's keyring code. The `assoc_array_find()` function, used for looking up keys, was called without holding the necessary Read-Copy-Update (RCU) read lock. This oversight allows for a memory corruption vulnerability, particularly affecting persistent key handling, as the system's garbage collection mechanism can free memory while it is still in use. This could lead to a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-64015\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-64015\nhttps://lore.kernel.org/linux-cve-announce/2026071957-CVE-2026-64015-19c9@gregkh/T"
    ],
    "name": "CVE-2026-64015",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-20T00:00:00Z",
    "bugzilla": {
      "description": "kernel: i2c: stub: Reject I2C block transfers with invalid length",
      "id": "2502872",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502872"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\ni2c: stub: Reject I2C block transfers with invalid length\nThe I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses data->block[0]\nas the transfer length. The existing check only clamps it to avoid\noverrunning the chip->words[256] register array, but does not validate\nit against I2C_SMBUS_BLOCK_MAX (32), which is the limit of the union\ni2c_smbus_data.block buffer (34 bytes total). The driver is a\ndevelopment/test tool (CONFIG_I2C_STUB=m, not built by default)\nthat must be loaded with a chip_addr= parameter.\nA local user with access to /dev/i2c-* can issue an I2C_SMBUS ioctl\nwith I2C_SMBUS_I2C_BLOCK_DATA and data->block[0] > 32, causing\nstub_xfer() to read or write past the end of the union\ni2c_smbus_data.block buffer:\nBUG: KASAN: stack-out-of-bounds in stub_xfer (drivers/i2c/i2c-stub.c:223)\nRead of size 1 at addr ffff88800abcfd92 by task exploit/81\nCall Trace:\n<TASK>\nstub_xfer (drivers/i2c/i2c-stub.c:223)\n__i2c_smbus_xfer (drivers/i2c/i2c-core-smbus.c:593)\ni2c_smbus_xfer (drivers/i2c/i2c-core-smbus.c:536)\ni2cdev_ioctl_smbus (drivers/i2c/i2c-dev.c:391)\ni2cdev_ioctl (drivers/i2c/i2c-dev.c:478)\n__x64_sys_ioctl (fs/ioctl.c:583)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n</TASK>\nThe bug exists because i2c-stub implements .smbus_xfer directly,\nbypassing the I2C_SMBUS_BLOCK_MAX validation in\ni2c_smbus_xfer_emulated(). The I2C_SMBUS_BLOCK_DATA case in the same\nfunction correctly validates against I2C_SMBUS_BLOCK_MAX, but the\nI2C_SMBUS_I2C_BLOCK_DATA case does not.\nFix by rejecting transfers with data->block[0] == 0 or\ndata->block[0] > I2C_SMBUS_BLOCK_MAX with -EINVAL, consistent with\nboth the I2C_SMBUS_BLOCK_DATA case in the same function and the\nI2C_SMBUS_I2C_BLOCK_DATA validation in i2c_smbus_xfer_emulated().",
      "A flaw was found in the Linux kernel's `i2c-stub` driver. A local user with access to the `/dev/i2c-*` device can exploit this vulnerability by issuing an I2C System Management Bus (SMBus) input/output control (ioctl) command with a specially crafted block transfer length. This invalid length can cause the driver to read or write beyond the allocated buffer, leading to a stack-out-of-bounds error and a system crash, resulting in a Denial of Service (DoS)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-64191\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-64191\nhttps://lore.kernel.org/linux-cve-announce/2026072052-CVE-2026-64191-42fe@gregkh/T"
    ],
    "name": "CVE-2026-64191",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-25T00:00:00Z",
    "bugzilla": {
      "description": "kernel: fuse: re-lock request before returning from fuse_ref_folio()",
      "id": "2507098",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507098"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nfuse: re-lock request before returning from fuse_ref_folio()\nfuse_ref_folio() unlocks the request but does not re-lock it before\nreturning. fuse_chan_abort() can end the request and the async end\ncallback (eg fuse_writepage_free()) can free the args while the\nsubsequent copy chain logic after fuse_ref_folio() accesses them,\nleading to use-after-free issues.\nFix this by locking the request in fuse_ref_folio() before returning.",
      "A flaw was found in the Linux kernel's FUSE (Filesystem in Userspace) component. The `fuse_ref_folio()` function does not properly re-lock a request after unlocking it, which can lead to a use-after-free vulnerability. A local attacker could exploit this flaw to potentially execute arbitrary code or cause a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-64266\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-64266\nhttps://lore.kernel.org/linux-cve-announce/2026072558-CVE-2026-64266-67e6@gregkh/T"
    ],
    "name": "CVE-2026-64266",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-29T00:00:00Z",
    "bugzilla": {
      "description": "curl: libcurl: Credential leak via reused proxy connection during HTTP redirects",
      "id": "2461205",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461205"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-201",
    "details": [
      "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
      "A flaw was found in libcurl. When configured to use a .netrc file for credentials and follow HTTP redirects, libcurl can inadvertently send the password from the initial connection to the redirected host. This sensitive information disclosure occurs when both the original and redirect URLs use clear text HTTP, are performed over the same HTTP proxy, and the same connection is reused. This vulnerability, categorized as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200), could allow an attacker to obtain user credentials."
    ],
    "statement": "Moderate: A flaw in libcurl could lead to credential leakage. This issue occurs when libcurl is configured to use a `.netrc` file for credentials and follows HTTP redirects, potentially exposing passwords to the redirected host. Exploitation requires both the original and redirect URLs to be clear text HTTP, performed over the same HTTP proxy, and with connection reuse. The curl command-line tool is not affected by this vulnerability.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-02T00:00:00Z",
        "advisory": "RHSA-2026:12916",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.20.0-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "confidential-compute-attestation-tech-preview/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-operator-bundle",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-builder-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Fix deferred",
        "package_name": "openshift-sandboxed-containers/osc-rhel9-operator",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-operator-bundle",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/cluster-logging-rhel9-operator",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/eventrouter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/fluentd-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/log-file-metric-exporter-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/logging-view-plugin-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Logging Subsystem for Red Hat OpenShift",
        "fix_state": "Fix deferred",
        "package_name": "openshift-logging/vector-rhel9",
        "cpe": "cpe:/a:redhat:logging:5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Fix deferred",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6429\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6429\nhttps://curl.se/docs/CVE-2026-6429.html"
    ],
    "name": "CVE-2026-6429",
    "mitigation": {
      "value": "To prevent the credential leak, avoid using the combination of .netrc for credentials, clear text HTTP URLs, and an HTTP proxy when making requests with libcurl. This operational control prevents the specific conditions that enable the vulnerability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-25T00:00:00Z",
    "bugzilla": {
      "description": "kernel: tracing: Prevent out-of-bounds read in glob matching",
      "id": "2507227",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507227"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\ntracing: Prevent out-of-bounds read in glob matching\nString event fields are not necessarily NUL-terminated, so the filter\npredicate functions (filter_pred_string(), filter_pred_strloc() and\nfilter_pred_strrelloc()) pass the field length to the regex match\ncallbacks, and the length-aware matchers honour it.\nregex_match_glob() was the exception: it ignored the length and called\nglob_match(), which scans the string until it hits a NUL byte. Some\nstring fields are not NUL-terminated. One example is the dynamic char\narray of the xfs_* namespace tracepoints, which is copied without a\ntrailing NUL. For such a field, glob matching reads past the end of\nthe event field, causing a KASAN slab-out-of-bounds read in\nglob_match(), reached via regex_match_glob() and filter_match_preds()\nfrom the xfs_lookup tracepoint.\nAdd a length-bounded glob_match_len() and use it from regex_match_glob()\nso glob matching always stops at the field boundary. The matching loop\nis factored into a shared helper so glob_match() keeps its behaviour.",
      "A flaw was found in the Linux kernel's tracing subsystem. This vulnerability allows a local attacker to trigger an out-of-bounds read by providing specially crafted input to glob matching functions. The issue arises because these functions did not correctly handle string event fields that were not properly terminated. Successful exploitation could lead to the disclosure of sensitive information or cause a system crash, resulting in a denial of service (DoS)."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-64299\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-64299\nhttps://lore.kernel.org/linux-cve-announce/2026072506-CVE-2026-64299-ef17@gregkh/T"
    ],
    "name": "CVE-2026-64299",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-25T00:00:00Z",
    "bugzilla": {
      "description": "kernel: sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT",
      "id": "2507177",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507177"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nsched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT\nRT migration is done aggressively. When a CPU schedules out a high\npriority RT task for a lower priority task, it will look to see if there's\nany RT tasks that are waiting to run on another CPU that is of higher\npriority than the task this CPU is about to run. If it finds one, it will\npull that task over to the CPU and allow it to run there instead.\nNormally, this pulling is done by looking at the RT overloaded mask (rto)\nwhich contains all the CPUs in the scheduler domain with RT tasks that are\nwaiting to run due to a higher priority RT task currently running on their\nCPU. The CPU that is about to schedule a lower priority task will grab the\nrq lock of the overloaded CPU and move the RT task from that CPU's runqueue\nto the local one and schedule the higher priority RT task.\nThis caused issues when a lot of CPUs would schedule a lower priority task\nat the same time. They would all try to grab the same runqueue lock of\nthe CPU with the overloaded RT tasks. Only the first CPU that got in will\nget that task. All the others would wait until they got the runqueue lock\nand see there's nothing to pull and do nothing. On systems with lots of\nCPUs, this caused a large latency (up to 500us) which is beyond what\nPREEMPT_RT is to allow.\nThe solution to that was to create an RT_PUSH_IPI logic. When any CPU\nwanted to pull a task, instead of grabbing the runqueue lock of the\noverloaded CPU, it would start by sending an IPI to the overloaded CPU,\nand that IPI handler would have the CPU with the waiting RT task do a push\ninstead. Then that handler would send an IPI to the next CPU with\noverloaded RT tasks, and so on. Note, after the first CPU starts this\nprocess, if another CPU wanted to do a pull, it would see that the process\nhas already begun and would only increment a counter to have the IPIs\ncontinue again.\nThe RT_PUSH_IPI solved the latency problem with PREEMPT_RT but could cause\na new issue with non PREEMPT_RT. Namely, softirqs run in a threaded\ncontext on PREEMPT_RT but they can run in an interrupt context in non-RT.\nIf an IPI lands on a CPU that has just woken up multiple RT tasks and the\ncurrent CPU is running a non RT or a low priority RT task, instead of\ndoing a push, it would simply do a schedule on that CPU. But if a softirq\nwas also executing on this CPU, the schedule would need to wait until the\nsoftirq finished. Until then, the CPU would still be considered overloaded\nas there are RT tasks still waiting to run on it.\nA live lock occurred on a workload that was doing heavy networking traffic\non a large machine where the softirqs would run 500us out of 750us. And it\nwould also be waking up RT tasks, causing the RT pull logic to be\nconstantly executed.\nWhen a softirq triggered on a CPU with RT tasks queued but not running\nyet, and the other CPUs would see this CPU as being overloaded, they would\nsend an IPI over to it. The CPU would notice that the waiting RT tasks are\nof higher priority than the currently running task and simply schedule\nthat CPU instead. But because the softirq was executing, before it could\nschedule, it would receive another IPI to do the same. The amount of IPIs\nwould slow down the currently running softirq so much that before it could\nreturn back to task context, it would execute another softirq never\nallowing the CPU to schedule. This live locked that CPU.\nAs RT_PUSH_IPI was created to help PREEMPT_RT, make it default off if\nPREEMPT_RT is not enabled.",
      "A flaw was found in the Linux kernel's real-time (RT) scheduler. In non-real-time configurations, the RT_PUSH_IPI mechanism, designed to improve task migration, can lead to a live lock. This occurs when a CPU handling heavy network traffic is repeatedly interrupted by other CPUs attempting to schedule waiting real-time tasks. The continuous interruptions prevent the CPU from processing tasks, resulting in a Denial of Service (DoS) for that CPU."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-64374\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-64374\nhttps://lore.kernel.org/linux-cve-announce/2026072523-CVE-2026-64374-a14e@gregkh/T"
    ],
    "name": "CVE-2026-64374",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-25T00:00:00Z",
    "bugzilla": {
      "description": "kernel: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()",
      "id": "2507296",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507296"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-825",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nwriteback: fix race between cgroup_writeback_umount() and inode_switch_wbs()\nWhen a container exits, the following BUG_ON() is occasionally triggered:\n==================================================================\nVFS: Busy inodes after unmount of sdb (ext4)\n------------[ cut here ]------------\nkernel BUG at fs/super.c:695!\nCPU: 3 PID: 6 Comm: containerd-shim Tainted: G OE K 6.6 #1\npstate: 63400009 (nZCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\npc : generic_shutdown_super+0xf0/0x100\nlr : generic_shutdown_super+0xf0/0x100\nCall trace:\ngeneric_shutdown_super+0xf0/0x100\nkill_block_super+0x20/0x48\next4_kill_sb+0x28/0x60\ndeactivate_locked_super+0x54/0x130\ndeactivate_super+0x84/0xa0\ncleanup_mnt+0xa4/0x140\n__cleanup_mnt+0x18/0x28\ntask_work_run+0x78/0xe0\ndo_notify_resume+0x204/0x240\n==================================================================\nThe root cause is a race between cgroup_writeback_umount() and\ninode_switch_wbs()/cleanup_offline_cgwb(). There is a window between\ninode_prepare_wbs_switch() returning true and the subsequent\nwb_queue_isw() call. Following is the process that triggers the issue:\nCPU A (umount)           |          CPU B (writeback)\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\ninode_switch_wbs/cleanup_offline_cgwb\natomic_inc(&isw_nr_in_flight)\ninode_prepare_wbs_switch\n-> passes SB_ACTIVE check\n__iget(inode)\ngeneric_shutdown_super\nsb->s_flags &= ~SB_ACTIVE\ncgroup_writeback_umount(sb)\nsmp_mb()\natomic_read(&isw_nr_in_flight)\nrcu_barrier()\n-> no pending RCU callbacks\nflush_workqueue(isw_wq)\n-> nothing queued, returns\nevict_inodes(sb)\n-> Inode skipped as isw still holds a ref.\nsop->put_super(sb)\n/* destroys percpu counters */\n-> VFS: Busy inodes after unmount!\nwb_queue_isw()\nqueue_work(isw_wq, ...)\n/* later in work function */\ninode_switch_wbs_work_fn\nprocess_inode_switch_wbs\niput() -> evict\npercpu_counter_dec() // UAF!\nFix this by extending the RCU read-side critical section in\ninode_switch_wbs() and cleanup_offline_cgwb() to cover from\ninode_prepare_wbs_switch() through wb_queue_isw().  Since there is\nno sleep in this window, rcu_read_lock() can be used.  Then add a\nsynchronize_rcu() in cgroup_writeback_umount() before the existing\nrcu_barrier(), so that all in-flight switchers that have passed the\nSB_ACTIVE check have completed queue_work() before flush_workqueue()\nis called.\nThe existing rcu_barrier() is intentionally retained so this fix can\nbe backported unchanged to stable kernels (5.10.y, 6.6.y, ...) that\nstill queue switches via queue_rcu_work(). It is a no-op on current\nmainline (since commit e1b849cfa6b6 (\"writeback: Avoid contention on\nwb->list_lock when switching inodes\")) and is removed in a follow-up\npatch.",
      "A flaw was found in the Linux kernel. A race condition exists between the `cgroup_writeback_umount()` and `inode_switch_wbs()` functions when a container exits. This race can lead to a kernel panic, resulting in a denial of service. This vulnerability could be triggered by a local user by exiting a container."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Under investigation",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-64378\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-64378\nhttps://lore.kernel.org/linux-cve-announce/2026072524-CVE-2026-64378-78c8@gregkh/T"
    ],
    "name": "CVE-2026-64378",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-07-25T00:00:00Z",
    "bugzilla": {
      "description": "kernel: smb/client: fix chown/chgrp with SMB3 POSIX Extensions",
      "id": "2507062",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507062"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-279",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nsmb/client: fix chown/chgrp with SMB3 POSIX Extensions\nOwnership (chown) and group (chgrp) modifications were being ignored when\nmounting with SMB3 POSIX Extensions unless CIFS_MOUNT_CIFS_ACL or\nCIFS_MOUNT_MODE_FROM_SID were also explicitly set.\nFix this by checking for posix_extensions in cifs_setattr_nounix() when\nupdating UID and GID, ensuring that id_mode_to_cifs_acl() is called to map\nand set the ownership/group information on the server.",
      "A flaw was found in the Linux kernel's Server Message Block (SMB) client. When mounting filesystems using SMB3 POSIX Extensions, modifications to file ownership (chown) and group (chgrp) were not correctly applied on the server unless specific mount options were also enabled. This could allow a local user to set incorrect file permissions, potentially leading to unauthorized access to sensitive information or unintended privilege escalation."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-64388\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-64388\nhttps://lore.kernel.org/linux-cve-announce/2026072527-CVE-2026-64388-82d9@gregkh/T"
    ],
    "name": "CVE-2026-64388",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-25T00:00:00Z",
    "bugzilla": {
      "description": "kernel: hwrng: virtio: clamp device-reported used.len at copy_data()",
      "id": "2507255",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507255"
    },
    "cvss3": {
      "cvss3_base_score": "7.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nhwrng: virtio: clamp device-reported used.len at copy_data()\nrandom_recv_done() stores the device-reported used.len directly into\nvi->data_avail.  copy_data() then indexes vi->data[] using\nvi->data_idx (advanced by previous copy_data() calls) and issues a\nmemcpy() without re-validating either value against the posted\nbuffer size sizeof(vi->data) (SMP_CACHE_BYTES bytes, typically 32\nor 64).\nA malicious or buggy virtio-rng backend can set used.len beyond\nsizeof(vi->data), steering the memcpy() past the end of the inline\narray into adjacent kmalloc-1k slab bytes.  hwrng_fillfn() mixes\nthose bytes into the guest RNG, and guest root can also observe\nthem directly via /dev/hwrng.\nConcrete impact is inside the guest:\n- Memory-safety / hardening: any virtio-rng backend that\nover-reports used.len causes the driver to read past vi->data\ninto unrelated slab contents.  hwrng_fillfn() is a kernel thread\nthat runs as soon as the device is probed; no guest userspace\ninteraction is required to first-trigger the OOB.\n- Cross-boundary leak (confidential-compute threat model): a\nmalicious hypervisor cooperating with a malicious or compromised\nguest root userspace can use /dev/hwrng as a leak channel for\nguest-kernel heap data.  The host sets a large used.len, guest\nroot reads /dev/hwrng, and the returned bytes contain guest\nkernel slab contents that were adjacent to vi->data.  In\npractice, confidential-compute guests (SEV-SNP, TDX) usually\ndisable virtio-rng entirely, so this path is narrow, but the\nfix is still worth carrying because the underlying\nmemory-safety bug contaminates the guest RNG on any host.\nKASAN confirms the OOB on a 7.1-rc4 guest whose virtio-rng backend\nhas been patched to report used.len = 0x10000:\nBUG: KASAN: slab-out-of-bounds in virtio_read+0x394/0x5d0\nRead of size 64 at addr ffff88800ae0ba20 by task hwrng/52\nCall Trace:\n__asan_memcpy+0x23/0x60\nvirtio_read+0x394/0x5d0\nhwrng_fillfn+0xb2/0x470\nkthread+0x2cc/0x3a0\nAllocated by task 1:\nprobe_common+0xa5/0x660\nvirtio_dev_probe+0x549/0xbc0\nThe buggy address belongs to the object at ffff88800ae0b800\nwhich belongs to the cache kmalloc-1k of size 1024\nThe buggy address is located 0 bytes to the right of\nallocated 544-byte region [ffff88800ae0b800, ffff88800ae0ba20)\nSame class of bug as commit c04db81cd028 (\"net/9p: Fix buffer\noverflow in USB transport layer\"), which hardened\nusb9pfs_rx_complete() against unchecked device-reported length in\nthe USB 9p transport.\nWith the clamp at point of use and array_index_nospec() in place,\nthe same harness boots cleanly: copy_data() returns zero for the\nbogus report, the device-supplied bytes after data_idx are\ndiscarded, and the driver issues a fresh request.",
      "A flaw was found in the Linux kernel's virtio-rng driver. A malicious or buggy virtualized hardware random number generator (virtio-rng) backend can report an overly large data length to the guest operating system. This unchecked length can lead to an out-of-bounds read, causing the driver to access memory beyond its intended buffer. This vulnerability can result in information disclosure, where sensitive guest-kernel heap data may be leaked to a malicious hypervisor or a compromised guest root user."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "erlang27",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "moderate"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-64456\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-64456\nhttps://lore.kernel.org/linux-cve-announce/2026072542-CVE-2026-64456-ccb5@gregkh/T"
    ],
    "name": "CVE-2026-64456",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-27T00:00:00Z",
    "bugzilla": {
      "description": "kernel: drm/edid: fix OOB read in drm_parse_tiled_block()",
      "id": "2507814",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507814"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\ndrm/edid: fix OOB read in drm_parse_tiled_block()\ndrm_parse_tiled_block() casts the DisplayID block to a\nstruct displayid_tiled_block and reads the full fixed layout up to\ntile->topology_id[7] without checking block->num_bytes. The DisplayID\niterator only validates the declared payload length, so a crafted EDID\ncan advertise a tiled-display block (tag DATA_BLOCK_TILED_DISPLAY, or\nDATA_BLOCK_2_TILED_DISPLAY_TOPOLOGY for v2.0) with a small num_bytes at\nthe end of a DisplayID extension. The read then runs past the end of the\nexact-sized kmemdup()'d EDID allocation, a heap out-of-bounds read.\nReject blocks shorter than the spec's 22-byte tiled payload before\nreading the fixed struct, as drm_parse_vesa_mso_data() already does.\nBUG: KASAN: slab-out-of-bounds in drm_edid_connector_update\nRead of size 2 at addr ffff888010077700 by task exploit/147\ndump_stack_lvl (lib/dump_stack.c:94 ...)\nprint_report (mm/kasan/report.c:378 ...)\nkasan_report (mm/kasan/report.c:595)\ndrm_edid_connector_update (drivers/gpu/drm/drm_edid.c:7581)\nbochs_connector_helper_get_modes (drivers/gpu/drm/tiny/bochs.c:574)\ndrm_helper_probe_single_connector_modes (drivers/gpu/drm/drm_probe_helper.c:426)\nstatus_store (drivers/gpu/drm/drm_sysfs.c:219)\n...\nvfs_write (fs/read_write.c:595 fs/read_write.c:688)\nksys_write (fs/read_write.c:740)",
      "A flaw was found in the Linux kernel. A specially crafted Extended Display Identification Data (EDID), which describes display capabilities, can cause a heap out-of-bounds read in the `drm_parse_tiled_block()` function within the `drm/edid` component. This vulnerability could lead to system instability or the disclosure of sensitive information."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:10",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "moderate"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-64546\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-64546\nhttps://lore.kernel.org/linux-cve-announce/2026072736-CVE-2026-64546-44ba@gregkh/T"
    ],
    "name": "CVE-2026-64546",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-14T00:00:00Z",
    "bugzilla": {
      "description": "kernel: XFS data corruption using reflink",
      "id": "2498915",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498915"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-362",
    "details": [
      "In the Linux kernel, the following vulnerability has been resolved:\nxfs: resample the data fork mapping after cycling ILOCK\nxfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode,\na data fork mapping, and a cow fork mapping.  Unfortunately, these two\nhelpers cycle the ILOCK to grab a transaction, which means that the\nmappings are stale as soon as we reacquire the ILOCK.  Currently we\nrefresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but\nwe don't refresh the data fork mapping beforehand, which means that the\nxfs_bmap_trim_cow in that function queries the refcount btree about the\nwrong physical blocks and returns an inaccurate value in *shared.\nIf *shared is now false, the directio write proceeds with a stale data\nfork mapping.  Fix this by querying the data fork mapping if the\nsequence counter changes across the ILOCK cycle.",
      "A flaw was found in the XFS filesystem. A race condition in the copy-on-write mechanism for reflinked files can cause writes to bypass the copy-on-write process and modify shared data blocks directly. As a result, data intended for a private copy may be written to the original shared location, corrupting the contents of other files that reference those blocks. A local attacker with read access to a file on an XFS filesystem with reflink enabled could exploit this flaw to corrupt files they do not have write access to, allowing content to be added to the target file. If properly exploited this vulnerability may lead to privilege escalations or arbitrary code execution."
    ],
    "statement": "This flaw affects XFS filesystems that have the reflink feature enabled (reflink=1), which is the default configuration for XFS filesystems created on Red Hat Enterprise Linux 8 and later. The issue is a race condition where internal file mapping information becomes stale during a lock cycle but is not refreshed before being used to determine whether data blocks are shared between files. Exploitation requires local access and read permission to the target file. Systems using XFS without reflink enabled, or using other filesystems such as ext4, are not affected. Red Hat Enterprise Linux 7 and earlier are not affected, as the reflink feature is not available on those versions.\nIn OpenShift Container Platform 4, this flaw is rated Low. RHCOS nodes do not have non-root local user accounts, so the local unprivileged attacker position required for exploitation does not exist in the default node configuration. Containers are isolated from host files by VFS filesystem identity boundaries — the container overlay and host mounts present different filesystem identities, causing cross-mount reflink operations to fail with EXDEV. The RHCOS composefs overlay further protects OS-managed files, including all SUID binaries, by mounting them read-only on a separate filesystem identity. CRI-O injects a per-container /etc/passwd on tmpfs rather than XFS, so the primary exploit target is not reachable from within a container. Containers with hostPath write access to sensitive host paths such as /etc already have equivalent privilege without this flaw.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39494",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "kernel-0:6.12.0-211.34.1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46951",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "kpatch-patch"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:41062",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "kernel-0:6.12.0-55.89.1.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39180",
        "cpe": "cpe:/a:redhat:enterprise_linux:8::nfv",
        "package": "kernel-rt-0:4.18.0-553.144.1.rt7.485.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39179",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "kernel-0:4.18.0-553.144.1.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47998",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "kpatch-patch"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39984",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "kernel-0:4.18.0-305.198.1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39984",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "kernel-0:4.18.0-305.198.1.el8_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-07-17T00:00:00Z",
        "advisory": "RHBA-2026:41254",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "kernel-0:4.18.0-372.202.1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-07-17T00:00:00Z",
        "advisory": "RHBA-2026:41254",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "kernel-0:4.18.0-372.202.1.el8_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-07-17T00:00:00Z",
        "advisory": "RHSA-2026:41229",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "kernel-0:4.18.0-477.154.1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-17T00:00:00Z",
        "advisory": "RHSA-2026:41229",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "kernel-0:4.18.0-477.154.1.el8_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:48016",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "kpatch-patch"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHBA-2026:39332",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "kernel-0:5.14.0-687.26.1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHBA-2026:39332",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "kernel-0:5.14.0-687.26.1.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47981",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "kpatch-patch"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHBA-2026:41013",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "kernel-0:5.14.0-284.182.1.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47997",
        "cpe": "cpe:/o:redhat:rhel_e4s:9.2",
        "package": "kpatch-patch"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:41063",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "kernel-0:5.14.0-427.138.1.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47984",
        "cpe": "cpe:/o:redhat:rhel_e4s:9.4",
        "package": "kpatch-patch"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-16T00:00:00Z",
        "advisory": "RHSA-2026:40425",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "kernel-0:5.14.0-570.128.1.el9_6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:47983",
        "cpe": "cpe:/o:redhat:rhel_eus:9.6",
        "package": "kpatch-patch"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "kernel-rt",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux for NVIDIA 26",
        "fix_state": "Affected",
        "package_name": "kernel",
        "cpe": "cpe:/a:redhat:enterprise_linux_nvidia:"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-64600\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-64600\nhttps://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt"
    ],
    "name": "CVE-2026-64600",
    "mitigation": {
      "value": "This vulnerability can be mitigated using a SystemTap script. To create and apply the mitigation, follow the steps below:\n1. Install and configure SystemTap\nInstall the SystemTap package and its dependencies following the instructions at:\nhttps://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/monitoring_and_managing_system_status_and_performance/getting-started-with-systemtap\n2. Create the mitigation script\nCreate a file named `refluxfs_mitigation.stp` with the following contents:\n~~~\nprobe begin {\nprintf(\"refluxfs mitigation loaded\\n\")\n}\nprobe module(\"xfs\").function(\"xfs_file_remap_range\").call {\n$remap_flags = 0xffff\n}\nprobe module(\"xfs\").function(\"xfs_file_remap_range\").return {\n$return = -95\n}\nprobe end {\nprintf(\"refluxfs mitigation unloaded\\n\")\n}\n~~~\n3. Load the mitigation\nAs the `root` user, execute SystemTap in guru mode:\n~~~\nstap -g refluxfs_mitigation.stp\n~~~\nOnce the script is compiled and loaded, the following message will appear:\n~~~\nrefluxfs mitigation loaded\n~~~\nWith the mitigation active, any application attempting to use reflink to copy files will receive `-EOPNOTSUPP` (`-95`) when calling the `FICLONE` ioctl (or its variants) or the `copy_file_range()` syscall.\nImportant considerations:\n1. SystemTap scripts are compiled into kernel modules. On systems with Secure Boot enabled, the kernel is in lockdown mode and will only load modules signed with a valid Secure Boot key or a key enrolled in the MOK. SystemTap can sign the generated module at compile time, but the user is responsible for key management. For instructions, refer to the \"Sign a SystemTap module\" section of:\nhttps://www.redhat.com/en/blog/secure-boot-systemtap\n2. The SystemTap module is not persistent across reboots. If the machine is restarted or the `stap` process is terminated, the module will be unloaded and the mitigation must be reapplied.\n3. Programs that rely on CoW/reflink without a fallback mechanism may fail, as reflink operations will be unavailable on any XFS filesystem while the mitigation is loaded. This includes the `cp` command when run with `--reflink=always`. In that case, use `--reflink=auto` instead, which is the default behavior in Red Hat Enterprise Linux.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-06-14T08:37:48Z",
    "bugzilla": {
      "description": "libcupsfilters: cups-filters: libcupsfilters: CUPS image filter process abort via malformed PNG",
      "id": "2502801",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502801"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-248",
    "details": [
      "A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.",
      "A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job."
    ],
    "statement": "This Moderate denial-of-service flaw in libcupsfilters and cups-filters allows an unauthenticated attacker to crash the CUPS image filter process. By submitting a specially crafted PNG print job, an attacker can trigger an abort, impacting only the in-flight print job rather than the overall CUPS service stability.",
    "acknowledgement": "Red Hat would like to thank Michalis Vasileiadis for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-19T00:00:00Z",
        "advisory": "RHSA-2026:56965",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libcupsfilters-1:2.0.0-13.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57451",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "cups-filters-0:1.20.0-36.el8_10.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58560",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "cups-filters-0:1.28.7-27.el9_8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "cups-filters",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "cups-filters",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-64612\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-64612\nhttps://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch"
    ],
    "name": "CVE-2026-64612",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-24T16:32:39Z",
    "bugzilla": {
      "description": "libssh2: libssh2: Arbitrary code execution via double-free in SFTP session",
      "id": "2506857",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506857"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1341",
    "details": [
      "libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.",
      "A flaw was found in libssh2. A malicious SSH (Secure Shell) server can exploit a double-free vulnerability in the sftp_open() function. This flaw allows the server to corrupt the heap memory of an authenticated client when it opens an SFTP (SSH File Transfer Protocol) session. This heap corruption can lead to arbitrary code execution on the client system, giving the attacker control over the affected system."
    ],
    "statement": "Moderate: A double-free vulnerability in libssh2 allows a malicious SSH server to corrupt the heap of an authenticated client during an SFTP session. This flaw requires user interaction, as a client must connect to a specially crafted server and initiate an SFTP transfer, which can lead to arbitrary code execution on the client system.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46927",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libssh2-main-1.11.1-10.2.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-66032\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-66032\nhttps://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0\nhttps://github.com/libssh2/libssh2/pull/2180\nhttps://www.vulncheck.com/advisories/libssh2-double-free-heap-corruption-via-sftp-open"
    ],
    "name": "CVE-2026-66032",
    "mitigation": {
      "value": "Restrict your libssh2 clients to connect only to fully trusted, internal SFTP servers to eliminate exposure to malicious server responses. Additionally, configure dependent applications with Restart=on-failure in systemd so RHEL's glibc memory protections can safely crash and auto-recover the process during an attack.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-24T16:42:18Z",
    "bugzilla": {
      "description": "libssh2: libssh2: Information disclosure and potential arbitrary code execution via heap out-of-bounds read",
      "id": "2506860",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506860"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.",
      "A missing bounds check in the libssh2 publickey subsystem allows malicious SSH servers to trigger a client-side out-of-bounds read, leaking heap pointers that could enable security bypasses, denial of service, or code execution."
    ],
    "statement": "This Moderate impact flaw in libssh2 allows a malicious SSH server to trigger an out-of-bounds read on a connecting client. While requiring user interaction to connect to a compromised server and having high attack complexity, successful exploitation could leak heap pointers, potentially aiding in ASLR bypass and leading to arbitrary code execution or denial of service on Red Hat Hardened Images.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-27T00:00:00Z",
        "advisory": "RHSA-2026:46927",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libssh2-main-1.11.1-10.2.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "libssh2",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-66034\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-66034\nhttps://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9\nhttps://github.com/libssh2/libssh2/pull/2202\nhttps://www.vulncheck.com/advisories/libssh2-heap-out-of-bounds-read-via-publickey-subsystem"
    ],
    "name": "CVE-2026-66034",
    "mitigation": {
      "value": "To mitigate this, strictly avoid connecting to untrusted SSH servers and enforce this policy using outbound network firewalls to block unknown IP addresses. For defense-in-depth, utilize OS-level memory protections and service sandboxing to contain any accidental exposure.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-28T14:29:05Z",
    "bugzilla": {
      "description": "tomcat: Apache Tomcat: Denial of Service via WebSocket chat example",
      "id": "2508085",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508085"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.\nThis issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.\nUsers are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.",
      "A flaw was found in Apache Tomcat. This uncontrolled resource consumption vulnerability, located in the WebSocket chat example, allows a remote attacker to cause a Denial of Service (DoS) by exhausting system resources. This can lead to the affected system becoming unresponsive or crashing."
    ],
    "statement": "This Moderate severity flaw in Apache Tomcat's WebSocket chat example could lead to a denial of service. The impact is limited as the vulnerable component is part of an example application, which is generally not deployed in production environments. Exploitation requires the example application to be present and accessible.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56039",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "tomcat11-main-11.0.25-0.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "tomcat9",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "tomcat6",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "pki-servlet-engine",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "tomcat",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Affected",
        "package_name": "tomcat10",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat JBoss Web Server 5",
        "fix_state": "Not affected",
        "package_name": "jws5-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Not affected",
        "package_name": "jws6-tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7",
        "fix_state": "Not affected",
        "package_name": "tomcat",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-66299\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-66299\nhttps://lists.apache.org/thread/8owczcc1o8qw1rxmg9gvfk4w2jnh4l5k"
    ],
    "name": "CVE-2026-66299",
    "mitigation": {
      "value": "To mitigate this vulnerability, remove the `examples` web application from your Apache Tomcat installation. This can typically be achieved by deleting the `examples` directory or `examples.war` file from the `webapps` directory of your Tomcat installation. A restart of the Tomcat service may be required for the changes to take full effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-25T00:08:35Z",
    "bugzilla": {
      "description": "redis: Redis: Remote Code Execution via specially crafted RESTORE payload",
      "id": "2506985",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506985"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1341",
    "details": [
      "Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.",
      "A flaw was found in Redis. An authenticated attacker, in an unusual configuration where they can execute the RESTORE command, could exploit a double free vulnerability. This occurs when a specially crafted RESTORE payload references the same NACK (pending entry) by multiple consumers, and both consumers are subsequently deleted via XGROUP DELCONSUMER. Successful exploitation of this flaw could lead to remote code execution."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-22T00:00:00Z",
        "advisory": "RHSA-2026:43236",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "valkey-main-9.0.5-0.1.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "valkey",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "redis:6/redis",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "redis",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "redis:7/redis",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "valkey",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "boost",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "impact": "important"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-66373\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-66373\nhttps://github.com/berabuddies/redis-poc\nhttps://github.com/redis/redis/compare/8.6.4...8.8.0\nhttps://github.com/redis/redis/pull/15081\nhttps://news.ycombinator.com/item?id=49024938\nhttps://x.com/Fried_rice/status/2080059356322918777"
    ],
    "name": "CVE-2026-66373",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-30T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "status": ""
    },
    "cwe": "",
    "details": [
      "The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6691\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6691"
    ],
    "name": "CVE-2026-6691",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-10T04:19:15Z",
    "bugzilla": {
      "description": "php: php-soap: php-src: PHP SOAP extension: Remote Code Execution via use-after-free vulnerability",
      "id": "2468560",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468560"
    },
    "cvss3": {
      "cvss3_base_score": "7.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.",
      "A flaw was found in PHP's SOAP extension. This vulnerability allows a remote attacker to execute arbitrary code on the affected system. The issue stems from a use-after-free error in the object deduplication mechanism, which can be triggered by sending a specially crafted SOAP request. This allows an attacker to manipulate memory and achieve remote code execution."
    ],
    "statement": "Red Hat systems which are operating as documented will not be running a PHP application in the root user context and so they will restrict the code execution to the context of the current working user. The host system may be affected by resource allocation induced by an attacker, but the impact will not be total.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22649",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php8.4-0:8.4.21-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23388",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php-0:8.3.31-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22305",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:8.2-8100020260521052503.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34354",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:7.4-8100020260604072603.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22142",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.3-9080020260521113736.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22143",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.2-9080020260521080715.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33449",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php-0:8.0.30-6.el9_8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6722\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6722\nhttps://github.com/php/php-src/security/advisories/GHSA-85c2-q967-79q5"
    ],
    "name": "CVE-2026-6722",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-10T03:27:00Z",
    "bugzilla": {
      "description": "PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation",
      "id": "2468562",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468562"
    },
    "cvss3": {
      "cvss3_base_score": "5.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "status": "verified"
    },
    "cwe": "CWE-79",
    "details": [
      "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.",
      "A flaw was found in PHP, specifically within the PHP-FPM status page. Due to improper sanitation of user data, a remote attacker can craft a malicious URL. When a user views the PHP-FPM status page with this crafted URL, it can lead to the execution of arbitrary JavaScript code (Cross-Site Scripting or XSS) on their machine, potentially compromising their browser session or leading to further attacks."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22649",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php8.4-0:8.4.21-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23388",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php-0:8.3.31-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22305",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:8.2-8100020260521052503.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34354",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:7.4-8100020260604072603.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22142",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.3-9080020260521113736.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22143",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.2-9080020260521080715.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33449",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php-0:8.0.30-6.el9_8"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14125",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "php-main-8.5.6-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6735\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6735\nhttps://github.com/php/php-src/security/advisories/GHSA-7qg2-v9fj-4mwv"
    ],
    "name": "CVE-2026-6735",
    "mitigation": {
      "value": "Restrict network access to the PHP-FPM status page to trusted internal networks or localhost. This can be achieved by configuring web server access controls (e.g., Apache httpd or Nginx) to deny external access to the status page URL. If the PHP-FPM status page functionality is not required, it should be disabled in the PHP-FPM configuration. Any changes to web server or PHP-FPM configuration may require a service reload or restart to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-10T18:41:25Z",
    "bugzilla": {
      "description": "glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion",
      "id": "2513603",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513603"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
      "A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the `wordexp` function can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-10T00:00:00Z",
        "advisory": "RHSA-2026:53069",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "glibc-main-2.43-8.1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "compat-glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "compat-glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "glibc",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "filesystem",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6791\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6791\nhttps://sourceware.org/bugzilla/show_bug.cgi?id=34091"
    ],
    "name": "CVE-2026-6791",
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-04-13T00:00:00Z",
    "bugzilla": {
      "description": "nano: nano: Local attacker can inject malicious .desktop launcher due to insecure directory permissions",
      "id": "2460018",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460018"
    },
    "cvss3": {
      "cvss3_base_score": "2.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N",
      "status": "draft"
    },
    "cwe": "CWE-732",
    "details": [
      "A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed.",
      "A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed."
    ],
    "statement": "This is a Low impact flaw where nano creates the `~/.local` directory with insecure permissions (0777) in permissive umask environments. A local attacker can exploit this to inject a malicious `.desktop` launcher. This issue affects Red Hat Enterprise Linux 8 and 9.",
    "acknowledgement": "Red Hat would like to thank Michał Majchrowicz, Marcin Wyczechowski (AFINE Team) for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "nano",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "nano",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "nano",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nano",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nano",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6842\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6842"
    ],
    "name": "CVE-2026-6842",
    "mitigation": {
      "value": "Ensure that the system's umask is configured to a secure value, such as `0022` or `0077`, to prevent the creation of world-writable directories. This can be set system-wide in `/etc/profile` or `/etc/bashrc`, or for individual users in their `~/.bashrc` or `~/.profile`. A secure umask will ensure that newly created directories, including `~/.local` by `nano`, have appropriate permissions.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-04-13T00:00:00Z",
    "bugzilla": {
      "description": "nano: nano: Format string vulnerability leads to Denial of Service",
      "id": "2460017",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460017"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-134",
    "details": [
      "A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Service (DoS) for the `nano` application.",
      "A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Service (DoS) for the `nano` application."
    ],
    "statement": "This Moderate impact vulnerability in nano allows an attacker to cause a denial of service by crafting a malicious directory name containing format string specifiers. When nano attempts to display an error message related to such a directory, it can lead to a crash. This affects Red Hat Enterprise Linux and OpenShift Container Platform.",
    "acknowledgement": "Red Hat would like to thank Michał Majchrowicz, Marcin Wyczechowski (AFINE Team) for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "nano",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "nano",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "nano",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "nano",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "nano",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6843\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6843"
    ],
    "name": "CVE-2026-6843",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-03T13:16:03Z",
    "bugzilla": {
      "description": "python-django: Django: Information disclosure via non-injective cookie salt derivation",
      "id": "2484373",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484373"
    },
    "cvss3": {
      "cvss3_base_score": "3.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-303",
    "details": [
      "An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15.\n`django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct `(name, salt)` pairs that produce the same concatenation.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Peng Zhou for reporting this issue.",
      "A flaw was found in Django. A remote attacker could exploit a non-injective salt derivation in `django.http.HttpRequest.get_signed_cookie` by crafting specific cookie name and salt argument pairs. This vulnerability allows the attacker to use a signed cookie in a different context than intended, potentially leading to information disclosure."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6873\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6873\nhttps://docs.djangoproject.com/en/dev/releases/security/\nhttps://groups.google.com/g/django-announce\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/"
    ],
    "name": "CVE-2026-6873",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-07-28T13:46:30Z",
    "bugzilla": {
      "description": "python: Python: Performance degradation in XML processing due to quadratic time complexity",
      "id": "2508122",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508122"
    },
    "cvss3": {
      "cvss3_base_score": "2.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.",
      "A flaw was found in Python's xml.etree.ElementPath component. This vulnerability can lead to a denial of service (DoS) when processing specially crafted XML documents. Specifically, certain XPath index predicates used with functions like Element.findall() and Element.iterfind() can cause the processing time to increase quadratically with the size of the input, making the system unresponsive. A remote attacker could exploit this by providing a malicious XML file, potentially disrupting service availability."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:48238",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-14-main-3.14.6-2.2.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:48246",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-10-main-3.10.20-3.2.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:48253",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-11-main-3.11.15-5.5.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:48278",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-13-main-3.13.14-1.7.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:48279",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-12-main-3.12.13-3.8.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54534",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-14-main-3.14.7-1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54554",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python3-13-main-3.13.15-1.hum1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6879\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6879\nhttps://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0\nhttps://github.com/python/cpython/issues/152674\nhttps://github.com/python/cpython/pull/152676\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"
    ],
    "name": "CVE-2026-6879",
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-05T14:50:02Z",
    "bugzilla": {
      "description": "django: Django: Information Disclosure via erroneous caching of Vary header with asterisk",
      "id": "2466771",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466771"
    },
    "cvss3": {
      "cvss3_base_score": "4.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-524",
    "details": [
      "An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.\n`django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Ahmad Sadeddin for reporting this issue.",
      "A flaw was found in Django. The `django.middleware.cache.UpdateCacheMiddleware` component incorrectly caches web requests when the `Vary` header contains an asterisk ('*'). This error can lead to sensitive private data being stored in the cache and subsequently served to unauthorized users, resulting in information disclosure."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Fix deferred",
        "package_name": "python-django20",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat OpenStack Platform 18.0",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:openstack:18.0"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite:el8/python-django",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Under investigation",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Update Infrastructure 4 for Cloud Providers",
        "fix_state": "Fix deferred",
        "package_name": "python-django",
        "cpe": "cpe:/a:redhat:rhui:4::el8"
      },
      {
        "product_name": "Self-service automation portal 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform/bootc-automation-portal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_portal:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-6907\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6907\nhttps://docs.djangoproject.com/en/dev/releases/security/\nhttps://groups.google.com/g/django-announce\nhttps://www.djangoproject.com/weblog/2026/may/05/security-releases/"
    ],
    "name": "CVE-2026-6907",
    "mitigation": {
      "value": "To mitigate this issue, disable the `django.middleware.cache.UpdateCacheMiddleware` in your Django application's `settings.py` file by removing it from the `MIDDLEWARE` list. This action prevents the erroneous caching of requests with an asterisk in the `Vary` header, thereby eliminating the information disclosure vulnerability. Be aware that disabling this middleware will also deactivate Django's built-in caching functionality, which may affect application performance and behavior. A restart of the Django application server is required for this change to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-25T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-7010\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-7010"
    ],
    "name": "CVE-2026-7010",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-28T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-7017\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-7017"
    ],
    "name": "CVE-2026-7017",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-13T08:29:08Z",
    "bugzilla": {
      "description": "curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse",
      "id": "2476979",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476979"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-201",
    "details": [
      "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
      "A flaw was found in libcurl. When a user performs a transfer over an HTTP proxy using Digest authentication and then reuses the same handle for a second transfer with a different proxy host, libcurl incorrectly sends the `Proxy-Authorization` header intended for the first proxy to the second proxy. This could lead to the disclosure of sensitive authentication information to an unintended proxy, potentially allowing an attacker to gain unauthorized access or impersonate the user."
    ],
    "statement": "Moderate: A flaw in libcurl allows for information disclosure when a client reuses a handle for HTTP proxy transfers. If a libcurl application uses Digest authentication with one proxy and then connects to a different proxy using the same handle, the `Proxy-Authorization` header from the initial connection may be inadvertently sent to the second proxy, potentially exposing sensitive authentication data.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-19T00:00:00Z",
        "advisory": "RHSA-2026:19106",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.20.0-2.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-7168\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-7168\nhttp://www.openwall.com/lists/oss-security/2026/04/29/14\nhttps://curl.se/docs/CVE-2026-7168.html\nhttps://curl.se/docs/CVE-2026-7168.json\nhttps://hackerone.com/reports/3697719"
    ],
    "name": "CVE-2026-7168",
    "mitigation": {
      "value": "To mitigate this issue, applications using libcurl should avoid reusing handles when switching between different HTTP proxies, especially after performing Digest authentication. This operational control prevents the unintended disclosure of `Proxy-Authorization` headers to subsequent proxy hosts.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-11T17:19:09Z",
    "bugzilla": {
      "description": "python: expat: Python/Expat: Denial of Service via crafted XML document",
      "id": "2469216",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2469216"
    },
    "cvss3": {
      "cvss3_base_score": "5.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "status": "draft"
    },
    "cwe": "CWE-331",
    "details": [
      "`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.",
      "A flaw was found in the `python` and `expat` components. Insufficient entropy in the hash-flooding protection mechanism of `xml.parsers.expat` and `xml.etree.ElementTree` allows a remote attacker to craft a malicious XML document. This crafted document can trigger a hash flooding attack, leading to a denial of service (DoS) condition."
    ],
    "statement": "The impact from this flaw is limited to a denial of service in the Python runtime. Host Red Hat systems are not affected in their default configurations.",
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Fix deferred",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Fix deferred",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python3.12",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "python3.14",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python3.12",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "python36:3.6/python36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.12",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.14",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "python3.9",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Fix deferred",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-cpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-cuda-12.9-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-cuda-13.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-neuron-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-rocm-6.4-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-rocm-7.0-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-rocm-7.1-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-spyre-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhai/base-image-tpu-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-automl-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-autorag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-built-in-detector-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-nlp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-caikit-tgis-serving-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-guardrails-detector-huggingface-runtime-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-autogluon-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-kserve-storage-initializer-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llm-d-inference-scheduler-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llm-d-kv-cache-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-llm-d-routing-sidecar-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-api-server-v2-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-ml-pipelines-runtime-generic-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-mlserver-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-modelmesh-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-modelmesh-runtime-adapter-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-openvino-model-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-pipelines-components-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-rhaii-cluster-validator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-rhaii-validator-tools-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-spark-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-training-rocm64-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-trustyai-service-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/rhai-cli-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-7210\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-7210\nhttps://github.com/python/cpython/issues/149018\nhttps://github.com/python/cpython/pull/149023\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/"
    ],
    "name": "CVE-2026-7210",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-10T04:28:14Z",
    "bugzilla": {
      "description": "PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions",
      "id": "2468561",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468561"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-839",
    "details": [
      "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.",
      "A flaw was found in PHP. Some functions, including `urldecode()`, incorrectly pass signed characters to character type (ctype) functions. On certain systems, this can lead to accessing memory with a negative offset. This vulnerability can be exploited by an attacker to trigger a denial of service (DoS), making the affected PHP application or system unavailable."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22649",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php8.4-0:8.4.21-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23388",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php-0:8.3.31-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22305",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:8.2-8100020260521052503.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34354",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:7.4-8100020260604072603.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22142",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.3-9080020260521113736.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22143",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.2-9080020260521080715.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33449",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php-0:8.0.30-6.el9_8"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-06T00:00:00Z",
        "advisory": "RHSA-2026:14125",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "php-main-8.5.6-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-7258\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-7258\nhttps://github.com/php/php-src/security/advisories/GHSA-m8rr-4c36-8gq4"
    ],
    "name": "CVE-2026-7258",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-10T04:13:26Z",
    "bugzilla": {
      "description": "php: NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()",
      "id": "2468564",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468564"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to mb_regex_encoding().",
      "A flaw was found in PHP. When an attacker input can influence the encoding passed to `mb_regex_encoding()` and the application subsequently uses mbregex search APIs, a NULL pointer dereference can occur due to a mismatch between the Oniguruma and mbfl encoding support. This issue can cause a crash in the PHP process, resulting in a denial of service."
    ],
    "statement": "To exploit this issue, an attacker needs to be able to influence the encoding passed to `mb_regex_encoding()` in a way that triggers a mismatch between the Oniguruma and mbfl encoding support. Also, the application must use the mbregex search APIs, allowing the attacker to cause a NULL pointer dereference. Due to these reasons, this flaw has been rated with a moderate severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23388",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php-0:8.3.31-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33449",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php-0:8.0.30-6.el9_8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "php8.4",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "php:7.4/php",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "php:8.2/php",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "php:8.2/php",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "php:8.3/php",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-7259\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-7259\nhttps://github.com/php/php-src/security/advisories/GHSA-wm6j-2649-pv75"
    ],
    "name": "CVE-2026-7259",
    "mitigation": {
      "value": "To mitigate this vulnerability, implement an encoding validation mechanism to reject the specific encodings and aliases that cause the mismatch between Oniguruma and mbfl. The following encodings and aliases are known to trigger this issue: iso-8859-11 and ISO8859-11, UJIS (EUC-JP alias), GB-2312 (EUC-CN alias), KOI-8R (KOI8 alias), and US_ASCII or ISO646 (ASCII aliases).",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-30T11:22:53Z",
    "bugzilla": {
      "description": "php: PHP: Denial of Service via circular symbolic links in phar archives",
      "id": "2509255",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509255"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-606",
    "details": [
      "Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.",
      "A flaw was found in PHP. When processing a specially crafted PHP Archive (phar) file containing circular symbolic links, the PHP process can enter an uncontrolled loop. This unbounded recursion exhausts the program's memory stack, causing the PHP application to crash. This vulnerability could allow an attacker to trigger a Denial of Service (DoS) condition, making the affected PHP service unavailable."
    ],
    "statement": "This Moderate impact flaw in PHP allows a local attacker to trigger a denial of service by providing a specially crafted phar archive containing circular symbolic links. Successful exploitation exhausts the C stack, leading to a PHP process crash, which can disrupt services utilizing PHP for archive processing.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57574",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:8.2-8100020260806050858.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57539",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.3-9080020260806131732.9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-28T00:00:00Z",
        "advisory": "RHSA-2026:47200",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "php-main-8.5.9-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "php8.4",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "php:7.4/php",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "php:8.2/php",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Fix deferred",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Fix deferred",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-7260\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-7260\nhttps://github.com/php/php-src/security/advisories/GHSA-vc5h-9ppw-p5f3"
    ],
    "name": "CVE-2026-7260",
    "mitigation": {
      "value": "To mitigate this issue, avoid processing phar archives from untrusted sources. If the `phar` extension is not essential for your application, consider disabling it in the PHP configuration. Disabling the `phar` extension may impact applications that rely on it for legitimate archive handling.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-10T04:07:25Z",
    "bugzilla": {
      "description": "PHP: PHP SoapServer: Memory corruption and information disclosure via incorrect persistence handling",
      "id": "2468563",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468563"
    },
    "cvss3": {
      "cvss3_base_score": "5.6",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "status": "verified"
    },
    "cwe": "CWE-825",
    "details": [
      "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.",
      "A flaw was found in the PHP SoapServer component. When the server is configured to maintain session persistence, an error during a SOAP request can cause the system to incorrectly manage memory. This can lead to a \"use-after-free\" vulnerability, where the system attempts to use memory that has already been released. An attacker could exploit this to corrupt memory, potentially exposing sensitive information or causing the system to crash, resulting in a denial of service."
    ],
    "statement": "This flaw only affects PHP users who have configured their runtime with the `SOAP_PERSISTENCE_SESSION` option which is not enabled by default. This flaw can lead to memory corruption, information disclosure, or service crashes. Normally, a SOAP server will only handle one SOAP request per PHP request, so it's unlikely that the attacker will be able to control the freed memory segment. Red Hat systems also employ address space layout randomization (ASLR) which makes accessing freed memory segments improbable.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22649",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php8.4-0:8.4.21-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23388",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php-0:8.3.31-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22305",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:8.2-8100020260521052503.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34354",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:7.4-8100020260604072603.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22142",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.3-9080020260521113736.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22143",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.2-9080020260521080715.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33449",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php-0:8.0.30-6.el9_8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-7261\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-7261\nhttps://github.com/php/php-src/security/advisories/GHSA-m33r-qmcv-p97q"
    ],
    "name": "CVE-2026-7261",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-10T04:00:09Z",
    "bugzilla": {
      "description": "php: NULL pointer dereference in SOAP apache:Map decoder with missing <value>",
      "id": "2468565",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468565"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-476",
    "details": [
      "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.  This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.",
      "A flaw was found in PHP. When a PHP SOAP server has a typemap configured, the apache:Map decoding process checks the incorrect variable in case of a missing value element. This incorrect check leads to a NULL pointer dereference and allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in a denial of service."
    ],
    "statement": "To exploit this issue, a remote unauthenticated attacker needs to send a malicious request to be processed by the apache:Map decoder, causing a crash in the PHP SOAP server process. Due to this reason, this vulnerability has been rated with an important severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22649",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php8.4-0:8.4.21-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23388",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php-0:8.3.31-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22305",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:8.2-8100020260521052503.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34354",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:7.4-8100020260604072603.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22142",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.3-9080020260521113736.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22143",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.2-9080020260521080715.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33449",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php-0:8.0.30-6.el9_8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-7262\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-7262\nhttps://github.com/php/php-src/security/advisories/GHSA-hmxp-6pc4-f3vv"
    ],
    "name": "CVE-2026-7262",
    "mitigation": {
      "value": "Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-15T12:09:03Z",
    "bugzilla": {
      "description": "perl-DBI: DBI: Arbitrary Code Execution on 32-bit Perl via Integer Wraparound",
      "id": "2516960",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2516960"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse.\npreparse reserves its output buffer with `newSV(strlen(statement) * 7 + 16)`, budgeting seven output bytes per input byte for the longest ':p99999' expansion. The product is computed in STRLEN, which is 32 bits wide on a 32-bit perl build, so a statement of 613,566,757 bytes multiplies to 4,294,967,299, wraps modulo 2^32 to 3, and reserves 19 bytes. The parser then copies the statement out through a raw pointer with no capacity check, writing the whole 585 MB input past the end of the allocation. The 99,999 placeholder limit does not bound this path, which is reached by ordinary non-placeholder content.\nAny caller that passes an untrusted statement of that length to preparse on a 32-bit perl gets a heap out-of-bounds write of attacker controlled bytes. Builds with a 64-bit STRLEN are not affected, since the wrap there needs a statement of about 2.3 exabytes.",
      "A flaw was found in DBI. On 32-bit Perl systems, a vulnerability exists in the `preparse` function due to an integer wraparound when calculating the output buffer size. A remote attacker can exploit this by providing a specially crafted, excessively large statement. This can lead to a heap out-of-bounds write, potentially allowing the attacker to execute arbitrary code or cause a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "perl-DBI:1.641/perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-73193\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-73193\nhttps://github.com/perl5-dbi/dbi/commit/c751ae5a5a6f56c2f8284f37c1f4d43500352ef1.patch\nhttps://github.com/perl5-dbi/dbi/security/advisories/GHSA-wj3v-c3hh-mhqr\nhttps://www.cve.org/CVERecord?id=CVE-2026-14739"
    ],
    "name": "CVE-2026-73193",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-08-15T12:09:22Z",
    "bugzilla": {
      "description": "perl-DBI: DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder",
      "id": "2516959",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2516959"
    },
    "cvss3": {
      "cvss3_base_score": "7.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "draft"
    },
    "cwe": "CWE-787",
    "details": [
      "DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse.\npreparse reserves seven output bytes per input byte, the width of the longest ':p99999' expansion. The ':N' branch parses the number with `atoi(src)` and assigns it to the binder counter with no range check, so a statement containing ':2147483648' leaves the counter negative (-2147483648 with glibc, where atoi wraps). Each following '?' then expands through `sprintf(start, \":p%d\", idx++)` to ':p-2147483648', 14 bytes with the terminating NUL where the buffer budgets 7. The placeholder limit added in 1.650 tests the counter against 99,999, which a negative counter passes.\nAny caller that preparses an untrusted statement into ':pN' style placeholders gets a heap out-of-bounds write that grows with the number of '?' marks following the poisoned placeholder. The '?' and '%s' return styles compare the parsed number against the expected sequence and error out, and are unaffected.",
      "A flaw was found in DBI for Perl. An unvalidated numeric placeholder in the `preparse` function can lead to a heap out-of-bounds write. When processing an untrusted statement, a specially crafted numeric placeholder can cause the binder counter to become negative. This results in subsequent placeholders expanding beyond their allocated buffer, leading to memory corruption. An attacker could exploit this to potentially achieve arbitrary code execution or cause a denial of service."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "perl-DBI:1.641/perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-73194\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-73194\nhttps://github.com/perl5-dbi/dbi/commit/29b72ae7d2a8114a734a55840bf1c45b89207809.patch\nhttps://github.com/perl5-dbi/dbi/security/advisories/GHSA-623j-hfpc-mrc4\nhttps://www.cve.org/CVERecord?id=CVE-2026-10879\nhttps://www.cve.org/CVERecord?id=CVE-2026-14739"
    ],
    "name": "CVE-2026-73194",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-09T00:00:00Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing",
      "id": "2481879",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary.",
      "A flaw was found in OpenSSL. A signed integer overflow vulnerability exists when sizing the destination buffer for Unicode output. This can lead to a heap buffer overflow, which may result in a crash or potentially allow an attacker to execute arbitrary code. Exploitation requires an application to directly call specific functions with a large amount of attacker-controlled input."
    ],
    "statement": "Low impact. This flaw in OpenSSL's ASN1_mbstring_ncopy() function, leading to a heap buffer overflow, is difficult to exploit in typical Red Hat environments. Exploitation requires an application to directly call the vulnerable function with an extremely large, attacker-controlled input (over half a gigabyte), a scenario not present in standard OpenSSL certificate or network protocol handling.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25237",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "openssl-1:3.5.5-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25239",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25239",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-4.el9_8"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34102",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1782890503"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Under investigation",
        "package_name": "jbcs-httpd24-openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Under investigation",
        "package_name": "jbcs-openssl-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Under investigation",
        "package_name": "jws-optional-native-components-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7",
        "fix_state": "Under investigation",
        "package_name": "jws-optional-native-components-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-7383\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-7383"
    ],
    "name": "CVE-2026-7383",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-17T00:00:00Z",
    "bugzilla": {
      "description": "bluez: BlueZ: Out-of-bounds read in AVRCP parse_media_element and parse_media_folder",
      "id": "2517490",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517490"
    },
    "cvss3": {
      "cvss3_base_score": "6.3",
      "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-125",
    "details": [
      "A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.",
      "A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device."
    ],
    "statement": "Red Hat ships BlueZ in Red Hat Enterprise Linux and related products. This out-of-bounds read vulnerability in the AVRCP profile requires a malicious Bluetooth device within radio range and user interaction to pair with that device. Successful exploitation could crash the bluetoothd daemon (denial of service) or expose limited heap memory contents.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "bluez",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "bluez",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "bluez",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "bluez",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "bluez",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-75032\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-75032"
    ],
    "name": "CVE-2026-75032",
    "mitigation": {
      "value": "Disable the AVRCP Bluetooth profile if it is not needed, or restrict Bluetooth pairing to trusted devices only. On systems where Bluetooth is not required, disable the Bluetooth subsystem entirely.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-10T03:42:36Z",
    "bugzilla": {
      "description": "php: signed integer overflow in metaphone()",
      "id": "2468566",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468566"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.",
      "A flaw was found in PHP. The metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. When an input string is longer than 2,147,483,647 bytes, a signed integer overflow can occur, leading to undefined behavior and an out-of-bounds read. This issue can cause a denial of service."
    ],
    "statement": "This issue can be exploited by passing an excessively large string, exceeding 2,147,483,647 bytes, to the metaphone() function. This function is used for searching and matching words based on their phonetic sound. The large string can lead to a signed integer overflow that allows an attacker to cause an out-of-bounds read, resulting in a denial of service. Due to these reasons, this vulnerability has been rated with an important severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-02T00:00:00Z",
        "advisory": "RHSA-2026:22649",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php8.4-0:8.4.21-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-04T00:00:00Z",
        "advisory": "RHSA-2026:23388",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "php-0:8.3.31-1.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22305",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:8.2-8100020260521052503.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34354",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "php:7.4-8100020260604072603.f7998665"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22142",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.3-9080020260521113736.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-01T00:00:00Z",
        "advisory": "RHSA-2026:22143",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php:8.2-9080020260521080715.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-30T00:00:00Z",
        "advisory": "RHSA-2026:33449",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "php-0:8.0.30-6.el9_8"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "php",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-7568\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-7568\nhttps://github.com/php/php-src/security/advisories/GHSA-96wq-48vp-hh57"
    ],
    "name": "CVE-2026-7568",
    "mitigation": {
      "value": "To mitigate this vulnerability, validate the length of any user-controlled input before passing it to the metaphone() function. Also, verify the PHP and web server configuration to ensure memory limits and maximum request sizes are restricted to below ~2 GiB.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-19T14:02:02Z",
    "bugzilla": {
      "description": "gitpython: GitPython: Arbitrary File Read via Crafted Parameters",
      "id": "2519621",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2519621"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-88",
    "details": [
      "GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with full file contents returned in GitCommandError.stderr.",
      "A flaw was found in GitPython where it fails to properly validate options provided to its git rm and git checkout commands. A remote attacker with low privileges could exploit this by supplying crafted parameters, such as --pathspec-from-file and --pathspec-file-nul. This vulnerability allows for arbitrary file disclosure, enabling the attacker to read any file accessible to the GitPython process."
    ],
    "statement": "GitPython before 3.1.58 does not validate options passed to the underlying `git rm` and `git checkout` commands in IndexFile.remove() and Head.checkout(). An attacker able to control the path/pathspec argument passed to these methods can inject the `--pathspec-from-file` and `--pathspec-file-nul` options and read arbitrary files accessible to the process, with the file contents returned in GitCommandError.stderr.\nExploitation requires an application to pass untrusted, attacker-controlled input directly as the path/pathspec argument to these GitPython methods; in normal use these arguments are supplied by the application or developer rather than by a remote adversary. Red Hat products that bundle GitPython use it as an internal build and automation helper with developer-controlled arguments and do not expose these parameters to untrusted input, so the vulnerable code cannot be controlled by an adversary in those products, which are therefore not affected. The GitPython library packages shipped in Red Hat OpenStack Platform contain the vulnerable code; those affected streams are out of support scope for this fix. Red Hat rates the impact of this flaw as Moderate.",
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Not affected",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Not affected",
        "package_name": "exploit-intelligence/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Migration Toolkit for Applications 8",
        "fix_state": "Not affected",
        "package_name": "mta/mta-solution-server-rhel9",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Not affected",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:1"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Not affected",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform-24/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform-24/hub-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "ansible-automation-platform-25/controller-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-25/hub-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Not affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "python3.11-gitpython",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "python3.12-gitpython",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "python3x-gitpython",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Out of support scope",
        "package_name": "python-gitpython",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Not affected",
        "package_name": "rhelai3/disk-image-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "llvm",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "llvm21",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "swift-lang",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-mlflow-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th-torch-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th-torch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-th-torch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-training-cuda128-torch29-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Out of support scope",
        "package_name": "GitPython",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/openstack-mistral-api",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/openstack-mistral-base",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/openstack-mistral-engine",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/openstack-mistral-event-engine",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/openstack-mistral-executor",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/openstack-nova-scheduler",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 16.2",
        "fix_state": "Not affected",
        "package_name": "rhosp-rhel8/openstack-tripleoclient",
        "cpe": "cpe:/a:redhat:openstack:16.2"
      },
      {
        "product_name": "Red Hat OpenStack Platform 17.1",
        "fix_state": "Out of support scope",
        "package_name": "GitPython",
        "cpe": "cpe:/a:redhat:openstack:17.1"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "python3.12-gitpython",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "python-gitpython",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vmaas-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-vulnerability-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-76217\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-76217\nhttps://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfc\nhttps://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-pathspec-from-file"
    ],
    "name": "CVE-2026-76217",
    "mitigation": {
      "value": "Applications using GitPython should not pass untrusted or attacker-controlled input directly as the path/pathspec argument to IndexFile.remove() or Head.checkout(), and should reject any such value beginning with a dash (\"-\") so that it cannot be interpreted as a git option. Updating GitPython to version 3.1.58 or later, which validates these options, resolves the issue.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-08-19T00:00:00Z",
    "bugzilla": {
      "description": "cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via CockpitLang cookie in send_login_html",
      "id": "2519497",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2519497"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-401",
    "details": [
      "A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.",
      "A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service."
    ],
    "statement": "Red Hat rates this issue as Moderate impact. Although cockpit-ws is reachable by an unauthenticated remote client and the resulting memory exhaustion can be sustained indefinitely, cockpit-ws is a stateless web console component: its crash or restart does not itself compromise the confidentiality or integrity of the host or of other running services, and the process is automatically restarted by systemd.",
    "acknowledgement": "Red Hat would like to thank Arpit Jain for reporting this issue.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "cockpit",
        "cpe": "cpe:/o:redhat:enterprise_linux:10",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "cockpit",
        "cpe": "cpe:/o:redhat:enterprise_linux:7",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "cockpit",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "cockpit",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "impact": "moderate"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/udi-base-rhel10",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/udi-base-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Not affected",
        "package_name": "devspaces/udi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-76235\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-76235"
    ],
    "name": "CVE-2026-76235",
    "mitigation": {
      "value": "Restrict network access to the cockpit port to trusted clients until a fix is available. No configuration-level mitigation removes the flaw entirely, since the login page must remain reachable without authentication.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-03T13:16:15Z",
    "bugzilla": {
      "description": "django: Django: Information disclosure via failed STARTTLS handshake in EmailBackend",
      "id": "2484369",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484369"
    },
    "cvss3": {
      "cvss3_base_score": "3.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-325",
    "details": [
      "An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15.\n`django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read email content via cleartext interception.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Kasper Dupont for reporting this issue.",
      "A flaw was found in Django. An on-path network attacker could exploit a vulnerability in `django.core.mail.backends.smtp.EmailBackend` where a partially-initialized connection is reused after a failed `STARTTLS` handshake when `fail_silently=True`. This could allow the attacker to intercept and read email content, leading to information disclosure."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-7666\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-7666\nhttps://docs.djangoproject.com/en/dev/releases/security/\nhttps://groups.google.com/g/django-announce\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/"
    ],
    "name": "CVE-2026-7666",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-09-09T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "8.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with q++ after every decoded delta and never checks it against the end of the heap-allocated luma/chroma plane buffers. The pointer is repositioned only when a sync marker introduces a new plane/row; between sync markers the run length is bounded solely by the input. A crafted PCD file that positions the pointer near the end of a plane and then supplies a long run of deltas with no intervening sync therefore walks the pointer past the end of the allocation and writes through it. Processing an untrusted PCD file — for example with gm convert or gm identify, or through any application linked against libGraphicsMagick — can corrupt heap memory beyond the buffers."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-77118\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-77118"
    ],
    "name": "CVE-2026-77118",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-10T20:48:51Z",
    "bugzilla": {
      "description": "perl-XML-LibXML: XML::LibXML: Denial of Service via truncated UTF-8 in XML node names",
      "id": "2468684",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468684"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-125",
    "details": [
      "XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences.\nA node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory.\nAny Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service.",
      "A flaw was found in XML::LibXML for Perl. A remote attacker could exploit this vulnerability when processing specially crafted XML node names containing incomplete UTF-8 character sequences. This can lead to an out-of-bounds read in heap memory, potentially causing the application to crash and resulting in a denial of service."
    ],
    "statement": "A flaw was found in perl-XML-LibXML. The XML::LibXML module reads out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi-byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory. Any Perl process that passes attacker-controlled strings to XML::LibXML's DOM node-name methods can trigger this flaw, with the likely consequence being a crash causing denial of service. The vulnerability is in the perl-XML-LibXML package specifically, not in the core perl interpreter. In containerised or pod-based deployments, the availability impact may be reduced since crashed processes are typically auto-restarted by the container orchestrator.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-14T00:00:00Z",
        "advisory": "RHSA-2026:39547",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "perl-XML-LibXML-1:2.0210-4.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39878",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "perl-XML-LibXML-1:2.0132-3.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-15T00:00:00Z",
        "advisory": "RHSA-2026:39553",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "perl-XML-LibXML-1:2.0206-5.el9_8.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "perl-XML-LibXML",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "perl-XML-LibXML",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-8177\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8177\nhttps://github.com/cpan-authors/XML-LibXML/commit/15652bd905a6c9dda59a81b14d4766adbbae2ea8.patch\nhttps://github.com/cpan-authors/XML-LibXML/issues/146"
    ],
    "name": "CVE-2026-8177",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-03T06:14:17Z",
    "bugzilla": {
      "description": "curl: curl: Insecure connection establishment due to TLS configuration mismatch",
      "id": "2496763",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-295",
    "details": [
      "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.",
      "A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established."
    ],
    "statement": "This is an Important flaw as `curl` may establish an insecure connection when attempting to upgrade a transfer with STARTTLS, potentially reusing an existing connection with mismatched TLS configurations. This could lead to unexpected data exposure or compromise, particularly in environments where `curl` is used for sensitive data transfers and relies on STARTTLS for security.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55450",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "curl-0:8.12.1-4.el10_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57462",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "curl-0:7.61.1-34.el8_10.13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55439",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "curl-0:7.76.1-40.el9_8.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55439",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "curl-0:7.76.1-40.el9_8.5"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29017",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.21.0-0.1.hum1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34975",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "rust-main-1.96.1-1.hum1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Not affected",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-8286\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8286\nhttps://curl.se/docs/CVE-2026-8286.html\nhttps://curl.se/docs/CVE-2026-8286.json\nhttps://hackerone.com/reports/3718195"
    ],
    "name": "CVE-2026-8286",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-14T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "status": ""
    },
    "cwe": "",
    "details": [
      "The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-8328\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8328"
    ],
    "name": "CVE-2026-8328",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-12T14:01:25Z",
    "bugzilla": {
      "description": "perl-libwww-perl: perl-libwww-perl: Information disclosure via cross-origin redirects",
      "id": "2476490",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476490"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-201",
    "details": [
      "LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects.\nOn a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the redirect target, including across scheme, host, or port changes.\nA redirect to an attacker controlled host therefore discloses the caller's credentials to that host.",
      "A flaw was found in LWP::UserAgent, a component of perl-libwww-perl. This vulnerability allows a remote attacker to obtain a user's credentials by redirecting a request to an attacker-controlled host. When processing a redirect, the LWP::UserAgent fails to properly strip Authorization and Proxy-Authorization headers, leading to their unintended disclosure across different origins."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "perl-libwww-perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "perl-libwww-perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "perl-libwww-perl:6.34/perl-libwww-perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "perl-libwww-perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-8368\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8368\nhttps://github.com/libwww-perl/libwww-perl/commit/9c4aeb6f2dd32f2b7eaf2d7827cade31ea6cb2c6.patch\nhttps://github.com/libwww-perl/libwww-perl/pull/284\nhttps://github.com/libwww-perl/libwww-perl/pull/512\nhttps://metacpan.org/release/OALDERS/libwww-perl-6.83/changes"
    ],
    "name": "CVE-2026-8368",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-25T23:53:27Z",
    "bugzilla": {
      "description": "perl: Perl: Heap buffer overflow when compiling regular expressions on 32-bit builds",
      "id": "2481312",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481312"
    },
    "cvss3": {
      "cvss3_base_score": "5.7",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": "draft"
    },
    "cwe": "CWE-131",
    "details": [
      "Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.",
      "A flaw was found in Perl. A remote attacker could exploit a heap buffer overflow vulnerability when compiling regular expressions with a repeated fixed string on 32-bit builds. Specifically, the `Perl_study_chunk` function in `regcomp_study.c` incorrectly calculates the size of the joined substring buffer, leading to an undersized memory allocation. This allows a subsequent copy operation to write past the end of the buffer, potentially enabling arbitrary code execution or causing a denial of service (DoS)."
    ],
    "statement": "Successful exploitation requires a specific application design where untrusted, attacker-controlled input is directly compiled as a regular expression by Perl.\nThe vulnerability is strictly limited to 32-bit architectures. \nStandard 64-bit deployments are not affected by this specific integer overflow flaw, significantly reducing the likelihood of exploitation in modern enterprise environments.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "perl:5.32/perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "perl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "fix_state": "Not affected",
        "package_name": "perl",
        "cpe": "cpe:/a:redhat:hummingbird:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-8376\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8376\nhttps://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch"
    ],
    "name": "CVE-2026-8376",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-03T13:16:29Z",
    "bugzilla": {
      "description": "Django: Django: Information disclosure due to improper handling of Cache-Control directives",
      "id": "2484370",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484370"
    },
    "cvss3": {
      "cvss3_base_score": "3.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "status": "draft"
    },
    "cwe": "CWE-1289",
    "details": [
      "An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.\n`django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Ahmed Badawe for reporting this issue.",
      "A flaw was found in Django. The `django.middleware.cache.UpdateCacheMiddleware` component does not correctly process `Cache-Control` response directives when they use uppercase or mixed-case values. This vulnerability allows a remote attacker to read responses that should not have been cached, leading to information disclosure."
    ],
    "package_state": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-24/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-25/lightspeed-rhel8",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/eda-controller-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/gateway-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/hub-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/lightspeed-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-27/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Fix deferred",
        "package_name": "automation-controller",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "fix_state": "Fix deferred",
        "package_name": "discovery/discovery-server-rhel9",
        "cpe": "cpe:/a:redhat:discovery:2::el9"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Self-service automation portal 2",
        "fix_state": "Under investigation",
        "package_name": "ansible-automation-platform/bootc-automation-portal-rhel9",
        "cpe": "cpe:/a:redhat:ansible_portal:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-8404\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8404\nhttps://docs.djangoproject.com/en/dev/releases/security/\nhttps://groups.google.com/g/django-announce\nhttps://www.djangoproject.com/weblog/2026/jun/03/security-releases/"
    ],
    "name": "CVE-2026-8404",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-20T20:11:14Z",
    "bugzilla": {
      "description": "HPLIP: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups",
      "id": "2480300",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480300"
    },
    "cvss3": {
      "cvss3_base_score": "9.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-190",
    "details": [
      "A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.",
      "A flaw was found in HP Linux Imaging and Printing Software (HPLIP). An integer overflow in the hpcups processing path when handling crafted print data may lead to arbitrary code execution or privilege escalation on the affected system."
    ],
    "statement": "HPLIP's hpcups component is vulnerable to integer overflow when processing crafted print data. A remote attacker who can submit print job content to the hpcups filter path may achieve arbitrary code execution or privilege escalation on systems using HPLIP for printing.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26228",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "hplip-0:3.23.12-10.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-30T00:00:00Z",
        "advisory": "RHSA-2026:48606",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "hplip-0:3.23.12-8.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26335",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "hplip-0:3.18.4-13.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:48960",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "hplip-0:3.18.4-9.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:48960",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "hplip-0:3.18.4-9.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:48961",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "hplip-0:3.18.4-9.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:48961",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "hplip-0:3.18.4-9.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:48959",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "hplip-0:3.18.4-9.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:48959",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "hplip-0:3.18.4-9.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26297",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "hplip-0:3.21.2-6.el9_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-30T00:00:00Z",
        "advisory": "RHSA-2026:48603",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "hplip-0:3.21.2-6.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-30T00:00:00Z",
        "advisory": "RHSA-2026:48586",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "hplip-0:3.21.2-6.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:48171",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "hplip-0:3.21.2-6.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "hplip",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "hplip",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-8631\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8631\nhttps://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118"
    ],
    "name": "CVE-2026-8631",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-20T20:14:36Z",
    "bugzilla": {
      "description": "HPLIP: HPLIP: Privilege escalation and arbitrary code execution via operating system command injection",
      "id": "2480297",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480297"
    },
    "cvss3": {
      "cvss3_base_score": "7.8",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-78",
    "details": [
      "A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via operating system command injection.",
      "A flaw was found in the HP Linux Imaging and Printing Software (HPLIP). This vulnerability may allow a local attacker to achieve escalation of privileges and/or arbitrary code execution through operating system command injection. This could lead to an attacker gaining unauthorized control over the affected system."
    ],
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26228",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "hplip-0:3.23.12-10.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-30T00:00:00Z",
        "advisory": "RHSA-2026:48606",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "hplip-0:3.23.12-8.el10_0.2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26335",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "hplip-0:3.18.4-13.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:48960",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "hplip-0:3.18.4-9.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:48960",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "hplip-0:3.18.4-9.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:48961",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "hplip-0:3.18.4-9.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:48961",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "hplip-0:3.18.4-9.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:48959",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "hplip-0:3.18.4-9.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-03T00:00:00Z",
        "advisory": "RHSA-2026:48959",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "hplip-0:3.18.4-9.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26297",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "hplip-0:3.21.2-6.el9_8.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-07-30T00:00:00Z",
        "advisory": "RHSA-2026:48603",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "hplip-0:3.21.2-6.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-07-30T00:00:00Z",
        "advisory": "RHSA-2026:48586",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "hplip-0:3.21.2-6.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-07-29T00:00:00Z",
        "advisory": "RHSA-2026:48171",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "hplip-0:3.21.2-6.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Will not fix",
        "package_name": "hplip",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "hplip",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-8632\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8632\nhttps://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118"
    ],
    "name": "CVE-2026-8632",
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-27T17:03:36Z",
    "bugzilla": {
      "description": "python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite",
      "id": "2460927",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460927"
    },
    "cvss3": {
      "cvss3_base_score": "8.0",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-22",
    "details": [
      "pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.",
      "A flaw was found in pip, the package installer for Python. A remote attacker can exploit this vulnerability by tricking a victim into installing a malicious Python wheel. This wheel contains specially crafted entry-point names that use directory traversal or absolute paths. This allows pip to write generated script wrappers outside the intended installation directory, leading to arbitrary file overwrite. This can severely impact system integrity and availability, and in certain scenarios, may lead to arbitrary code execution."
    ],
    "statement": "This Important flaw in pip's wheel installation process allows for arbitrary file overwrite due to path traversal. An attacker could exploit this by convincing a user to install a specially crafted malicious Python wheel. While file overwrites are limited to the installing user's permissions, using `pip install` with elevated privileges in Red Hat environments significantly increases the potential impact, potentially leading to system integrity compromise or arbitrary code execution.",
    "acknowledgement": "This issue was discovered by AISLE in partnership with Red Hat from.",
    "affected_release": [
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42078",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "automation-controller-0:4.6.30-2.el8ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42078",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
        "package": "automation-controller-0:4.6.30-2.el9ap"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42079",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "automation-controller-0:4.7.14-3.el9ap"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36193",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "python3.14-pip-0:25.2-3.el10_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36315",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "python3.14-pip-0:25.2-3.el9_8.5"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.5",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42144",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
        "package": "ansible-automation-platform-25/controller-rhel8:1784049109"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34374",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/de-minimal-rhel9:1782711769"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34374",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/de-supported-rhel9:1782713671"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34374",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/gateway-rhel9:1782761510"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-07-20T00:00:00Z",
        "advisory": "RHSA-2026:42132",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-tech-preview/metrics-service-rhel9:1783969139"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2.6",
        "release_date": "2026-08-04T00:00:00Z",
        "advisory": "RHSA-2026:50479",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2.6::el9",
        "package": "ansible-automation-platform-26/controller-rhel9:1785753810"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33313",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782763840"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-08-13T00:00:00Z",
        "advisory": "RHSA-2026:54760",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1786638573"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34891",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python-pip-main-26.1.1-3.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-07T00:00:00Z",
        "advisory": "RHSA-2026:36359",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "python-pip-main-26.1.2-1.hum1"
      },
      {
        "product_name": "Red Hat Migration Toolkit for Applications 8.2",
        "release_date": "2026-08-18T00:00:00Z",
        "advisory": "RHSA-2026:56347",
        "cpe": "cpe:/a:redhat:migration_toolkit_applications:8.2::el9",
        "package": "mta/mta-rhel9-operator:1786481481"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-caikit-tgis-serving-rhel9:1783082430"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-kserve-storage-initializer-rhel9:1783024305"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-modelmesh-runtime-adapter-rhel9:1783342900"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-training-cuda121-torch24-py311-rhel9:1783998418"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-training-cuda124-torch25-py311-rhel9:1783998418"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-training-rocm62-torch24-py311-rhel9:1782475830"
      },
      {
        "product_name": "Red Hat OpenShift AI 2.25",
        "release_date": "2026-07-21T00:00:00Z",
        "advisory": "RHSA-2026:42644",
        "cpe": "cpe:/a:redhat:openshift_ai:2.25::el9",
        "package": "rhoai/odh-training-rocm62-torch25-py311-rhel9:1782475830"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.0",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34772",
        "cpe": "cpe:/a:redhat:openshift_ai:3.0::el9",
        "package": "rhai/base-image-cpu-rhel9:1782929133"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.0",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34773",
        "cpe": "cpe:/a:redhat:openshift_ai:3.0::el9",
        "package": "rhai/base-image-spyre-rhel9:1782928984"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.0",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34774",
        "cpe": "cpe:/a:redhat:openshift_ai:3.0::el9",
        "package": "rhai/base-image-tpu-rhel9:1782968171"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.0",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34778",
        "cpe": "cpe:/a:redhat:openshift_ai:3.0::el9",
        "package": "rhai/base-image-cuda-rhel9:1782929069"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.0",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34780",
        "cpe": "cpe:/a:redhat:openshift_ai:3.0::el9",
        "package": "rhai/base-image-rocm-rhel9:1782928977"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.2",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34739",
        "cpe": "cpe:/a:redhat:openshift_ai:3.2::el9",
        "package": "rhai/base-image-cpu-rhel9:1782915416"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.2",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34752",
        "cpe": "cpe:/a:redhat:openshift_ai:3.2::el9",
        "package": "rhai/base-image-cuda-rhel9:1782915184"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.2",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34756",
        "cpe": "cpe:/a:redhat:openshift_ai:3.2::el9",
        "package": "rhai/base-image-spyre-rhel9:1782914833"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.2",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34758",
        "cpe": "cpe:/a:redhat:openshift_ai:3.2::el9",
        "package": "rhai/base-image-rocm-rhel9:1782914751"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.2",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34760",
        "cpe": "cpe:/a:redhat:openshift_ai:3.2::el9",
        "package": "rhai/base-image-tpu-rhel9:1782914629"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.2",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34765",
        "cpe": "cpe:/a:redhat:openshift_ai:3.2::el9",
        "package": "rhai/base-image-rocm-rhel9:1782914721"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34740",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhai/base-image-neuron-rhel9:1782915056"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34741",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhai/base-image-spyre-rhel9:1782916020"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34748",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhai/base-image-cuda-12.9-rhel9:1782914960"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34749",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhai/base-image-rocm-6.4-rhel9:1782914644"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34750",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhai/base-image-rocm-7.0-rhel9:1782914706"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34775",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhai/base-image-cuda-13.0-rhel9:1782915015"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34776",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhai/base-image-cpu-rhel9:1782914779"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34777",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhai/base-image-tpu-rhel9:1782914653"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-kserve-storage-initializer-rhel9:1783010225"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-mlserver-rhel9:1782887848"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-cuda121-torch24-py311-rhel9:1782471555"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-cuda124-torch25-py311-rhel9:1782471579"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-cuda128-torch28-py312-rhel9:1783073038"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-cuda128-torch29-py312-rhel9:1782991170"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-rocm62-torch24-py311-rhel9:1782471656"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-rocm62-torch25-py311-rhel9:1782471663"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-rocm64-torch28-py312-rhel9:1783069204"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.3",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37275",
        "cpe": "cpe:/a:redhat:openshift_ai:3.3::el9",
        "package": "rhoai/odh-training-rocm64-torch29-py312-rhel9:1782991170"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34456",
        "cpe": "cpe:/a:redhat:openshift_ai:3.4::el9",
        "package": "rhoai/odh-kserve-storage-initializer-rhel9:1782133213"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34456",
        "cpe": "cpe:/a:redhat:openshift_ai:3.4::el9",
        "package": "rhoai/odh-mlserver-rhel9:1782726504"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34456",
        "cpe": "cpe:/a:redhat:openshift_ai:3.4::el9",
        "package": "rhoai/odh-th06-cpu-torch210-py312-rhel9:1782135464"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34456",
        "cpe": "cpe:/a:redhat:openshift_ai:3.4::el9",
        "package": "rhoai/odh-th06-cuda130-torch210-py312-rhel9:1782136276"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34456",
        "cpe": "cpe:/a:redhat:openshift_ai:3.4::el9",
        "package": "rhoai/odh-th06-rocm64-torch291-py312-rhel9:1782135346"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34456",
        "cpe": "cpe:/a:redhat:openshift_ai:3.4::el9",
        "package": "rhoai/odh-training-cuda121-torch24-py311-rhel9:1782132167"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34456",
        "cpe": "cpe:/a:redhat:openshift_ai:3.4::el9",
        "package": "rhoai/odh-training-cuda124-torch25-py311-rhel9:1782132207"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34456",
        "cpe": "cpe:/a:redhat:openshift_ai:3.4::el9",
        "package": "rhoai/odh-training-cuda128-torch28-py312-rhel9:1782132237"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34456",
        "cpe": "cpe:/a:redhat:openshift_ai:3.4::el9",
        "package": "rhoai/odh-training-cuda128-torch29-py312-rhel9:1782132240"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34456",
        "cpe": "cpe:/a:redhat:openshift_ai:3.4::el9",
        "package": "rhoai/odh-training-rocm62-torch24-py311-rhel9:1782132286"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34456",
        "cpe": "cpe:/a:redhat:openshift_ai:3.4::el9",
        "package": "rhoai/odh-training-rocm62-torch25-py311-rhel9:1782132236"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34456",
        "cpe": "cpe:/a:redhat:openshift_ai:3.4::el9",
        "package": "rhoai/odh-training-rocm64-torch28-py312-rhel9:1782132163"
      },
      {
        "product_name": "Red Hat OpenShift AI 3.4",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34456",
        "cpe": "cpe:/a:redhat:openshift_ai:3.4::el9",
        "package": "rhoai/odh-training-rocm64-torch29-py312-rhel9:1782132297"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer 1.4",
        "release_date": "2026-07-09T00:00:00Z",
        "advisory": "RHSA-2026:37283",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1.4::el9",
        "package": "rhtas/model-transparency-rhel9:1782485441"
      }
    ],
    "package_state": [
      {
        "product_name": "Exploit Intelligence",
        "fix_state": "Affected",
        "package_name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "cpe": "cpe:/a:redhat:exploit_intelligence:0"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Affected",
        "package_name": "lightspeed-core/rag-tool-cpu-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Lightspeed Core",
        "fix_state": "Affected",
        "package_name": "lightspeed-core/rag-tool-cuda-12.9-rhel9",
        "cpe": "cpe:/a:redhat:lightspeed_core"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Affected",
        "package_name": "migration-toolkit-virtualization/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "Migration Toolkit for Virtualization",
        "fix_state": "Will not fix",
        "package_name": "mtv-candidate/mtv-rhel9-operator",
        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Lightspeed",
        "fix_state": "Not affected",
        "package_name": "openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9",
        "cpe": "cpe:/a:redhat:openshift_lightspeed"
      },
      {
        "product_name": "OpenShift Service Mesh 3",
        "fix_state": "Not affected",
        "package_name": "openshift-service-mesh/kiali-rhel9-operator",
        "cpe": "cpe:/a:redhat:service_mesh:3"
      },
      {
        "product_name": "Pen Drive Powered by Red Hat Lightspeed",
        "fix_state": "Affected",
        "package_name": "pen-drive/pen-drive-scanner-rhel9",
        "cpe": "cpe:/a:redhat:pdrive_lightspeed:1"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/model-opt-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaiis/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaiis/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-cpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-neuron-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Affected",
        "package_name": "rhaii/vllm-spyre-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat AI Inference Server",
        "fix_state": "Will not fix",
        "package_name": "rhaii/vllm-tpu-rhel9",
        "cpe": "cpe:/a:redhat:ai_inference_server:3"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/eda-controller-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/hub-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Will not fix",
        "package_name": "ansible-automation-platform-26/lightspeed-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-26/platform-resource-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-27/aap-cloud-billing-operator-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform/automation-dashboard-rhel9",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Ansible Automation Platform 2",
        "fix_state": "Affected",
        "package_name": "ansible-automation-platform-tech-preview/metrics-service-rhel9-operator",
        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Not affected",
        "package_name": "rhdh/rhdh-hub-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Developer Hub",
        "fix_state": "Will not fix",
        "package_name": "rhdh/rhdh-must-gather-rhel9",
        "cpe": "cpe:/a:redhat:rhdh:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "rhel10/python-312-minimal",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "ubi8/python-311",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "ubi8/python-312",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "ubi8/python-36",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "ubi8/python-39",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python3.12-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "python-pip",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "rhel9/python-311",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "rhel9/python-39",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "ubi9/python-312",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "ubi9/python-312-minimal",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-aws-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-azure-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-azure-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-gcp-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/bootc-rocm-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rhelai3/disk-image-cuda-rhel9",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat Enterprise Linux command line assistant",
        "fix_state": "Under investigation",
        "package_name": "rhel-cla/rhel-knowledge-bridge-rhel10",
        "cpe": "cpe:/a:redhat:rhel_cla:1"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-gaudi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhai/base-image-rocm-7.1-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-automl-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-autorag-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-built-in-detector-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-caikit-nlp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-feature-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-guardrails-detector-huggingface-runtime-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-kserve-autogluon-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-llama-stack-core-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-llm-d-kv-cache-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-model-registry-job-async-upload-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-pipelines-components-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Not affected",
        "package_name": "rhoai/odh-spark-operator-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-ta-lmes-job-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-vllm-cuda-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-vllm-rocm-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift AI (RHOAI)",
        "fix_state": "Affected",
        "package_name": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
        "cpe": "cpe:/a:redhat:openshift_ai"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift4/ose-ansible-rhel9-operator",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Not affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/udi-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/quay-rhel8",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Quay 3",
        "fix_state": "Not affected",
        "package_name": "quay/quay-rhel9",
        "cpe": "cpe:/a:redhat:quay:3"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/foreman-mcp-server-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-advisor-backend-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Not affected",
        "package_name": "satellite/iop-advisor-engine-rhel9",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Trusted Artifact Signer",
        "fix_state": "Affected",
        "package_name": "rhtas/segment-reporting-rhel9",
        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Not affected",
        "package_name": "stf/prometheus-webhook-snmp-rhel9",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Not affected",
        "package_name": "stf/service-telemetry-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      },
      {
        "product_name": "Service Telemetry Framework 1.5",
        "fix_state": "Not affected",
        "package_name": "stf/smart-gateway-rhel9-operator",
        "cpe": "cpe:/a:redhat:stf:1.5"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-8643\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8643\nhttps://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb"
    ],
    "name": "CVE-2026-8643",
    "mitigation": {
      "value": "To mitigate this issue, users should avoid installing Python wheels from untrusted sources. It is strongly advised against using `pip install` with elevated privileges, such as `sudo`, when installing wheels. Additionally, administrators should inspect `entry_points.txt` within wheels for path separators or absolute paths before installation.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-18T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "status": ""
    },
    "cwe": "",
    "details": [
      "HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.\n\nThe XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV's PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.\n\nThe read may disclose adjacent heap contents into the destination SV."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-8829\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8829"
    ],
    "name": "CVE-2026-8829",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Critical",
    "public_date": "2026-06-03T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "9.8",
      "cvss3_scoring_vector": "CVSS:3.1/",
      "status": ""
    },
    "cwe": "",
    "details": [
      "A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow. The attack may be initiated remotely. The patch is named 0c957ec03054eb6c8205e9c9d1d05d90ada3898c. It is suggested to install a patch to address this issue."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-8836\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8836"
    ],
    "name": "CVE-2026-8836",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-07-03T06:15:04Z",
    "bugzilla": {
      "description": "curl: curl: Cookie injection via malicious HTTP server using super cookies",
      "id": "2496765",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496765"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-565",
    "details": [
      "A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
      "A flaw was found in curl's cookie parsing logic. A malicious HTTP server can exploit this by setting 'super cookies' that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity."
    ],
    "statement": "Moderate: Red Hat rates this flaw Moderate (CVSS 6.5) compared to CISA's Critical (9.1). The scoring difference is due to two factors: first, exploitation requires the victim's curl to connect using a trailing-dot hostname (e.g., https://example.co.uk.), a format that is uncommon in practice and incompatible with TLS SNI; second, the direct impact is cookie injection into outbound requests — not exfiltration of victim data to the attacker. The curl project itself rates this flaw Low severity. Red Hat products that use curl for HTTP communication are affected, but the trailing-dot precondition significantly limits real-world exploitability. This flaw has not been shown to enable impacts beyond session integrity modification.",
    "affected_release": [
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29017",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.21.0-0.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34975",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "rust-main-1.96.1-1.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Not affected",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-8924\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8924\nhttps://curl.se/docs/CVE-2026-8924.html\nhttps://curl.se/docs/CVE-2026-8924.json\nhttps://hackerone.com/reports/3733905"
    ],
    "name": "CVE-2026-8924",
    "mitigation": {
      "value": "Do not use trailing-dot hostnames in URLs passed to curl. Trailing dots are uncommon and incompatible with TLS SNI. Upgrade to curl 8.21.0 to resolve",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-03T06:16:06Z",
    "bugzilla": {
      "description": "curl: Information disclosure due to uncleared proxy authentication state",
      "id": "2496769",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496769"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "status": "verified"
    },
    "cwe": "CWE-201",
    "details": [
      "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.",
      "A flaw was found in libcurl. When reusing a libcurl handle for sequential transfers with environment-variable proxy configuration, the library does not properly clear the proxy authentication state. This oversight can lead to the unintended disclosure of `Proxy-Authorization` headers to an incorrect proxy, potentially exposing sensitive authentication information to an unauthorized entity. This is an information disclosure vulnerability."
    ],
    "statement": "This Important information disclosure vulnerability in libcurl arises when a handle is reused for sequential transfers with environment-variable proxy configurations, failing to clear the proxy authentication state. This oversight can lead to `Proxy-Authorization` headers being inadvertently sent to an incorrect proxy, potentially exposing sensitive authentication information in Red Hat environments utilizing multiple proxy configurations. This flaw leads only to a confidentiality impact. There has been no observed integrity impact.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55432",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "curl-0:8.12.1-4.el10_2.4"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29017",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.21.0-0.1.hum1",
        "impact": "important"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34975",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "rust-main-1.96.1-1.hum1",
        "impact": "important"
      }
    ],
    "package_state": [
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "build-of-trustee/trustee-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Confidential Compute Attestation",
        "fix_state": "Affected",
        "package_name": "openshift-sandboxed-containers/osc-podvm-payload-rhel9",
        "cpe": "cpe:/a:redhat:confidential_compute_attestation:1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "igvm",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "s390utils",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Affected",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "rust",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Affected",
        "package_name": "snphost",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "trustee-guest-components",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "fix_state": "Affected",
        "package_name": "rust",
        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Affected",
        "package_name": "libcurl-1.dll",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Will not fix",
        "package_name": "libcurl.so",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Not affected",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-8927\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-8927\nhttps://curl.se/docs/CVE-2026-8927.html\nhttps://curl.se/docs/CVE-2026-8927.json\nhttps://hackerone.com/reports/3744543"
    ],
    "name": "CVE-2026-8927",
    "mitigation": {
      "value": "To mitigate this issue, applications utilizing libcurl should avoid reusing handles when switching between different proxy configurations. This operational control prevents the unintended leakage of `Proxy-Authorization` headers to incorrect proxies.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-20T07:30:00Z",
    "bugzilla": {
      "description": "389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS)",
      "id": "2480093",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480093"
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-770",
    "details": [
      "A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.",
      "A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service."
    ],
    "statement": "This vulnerability is rated Important for Red Hat products shipping 389-ds-base. A remote, unauthenticated attacker with network access to the LDAP port can send a single crafted LDAP request containing an excessive number of minimal controls, causing the server to perform unbounded memory allocations and consume significant CPU time. Under concurrent attack, this can degrade or deny directory service availability through worker thread starvation or out-of-memory conditions.\nThe vulnerability is mitigated in environments where the LDAP port is not exposed to untrusted networks (firewall/ACL restrictions). Additionally, lowering nsslapd-maxbersize reduces the maximum message size (and thus the upper bound on controls per message), though this does not fully eliminate the amplification since it caps bytes rather than control count. The definitive fix requires enforcing a maximum controls-per-message limit in the decode loop.",
    "acknowledgement": "Red Hat would like to thank Oleh Konko (1seal.org) for reporting this issue.",
    "affected_release": [
      {
        "product_name": "Red Hat Directory Server 11.5 E4S for RHEL 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26461",
        "cpe": "cpe:/a:redhat:directory_server_e4s:11.5::el8",
        "package": "redhat-ds:11-8060020260609102432.0ca98e7e"
      },
      {
        "product_name": "Red Hat Directory Server 11.7 E4S for RHEL 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26597",
        "cpe": "cpe:/a:redhat:directory_server_e4s:11.7::el8",
        "package": "redhat-ds:11-8080020260610130252.f969626e"
      },
      {
        "product_name": "Red Hat Directory Server 11.9 for RHEL 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26458",
        "cpe": "cpe:/a:redhat:directory_server:11.9::el8",
        "package": "redhat-ds:11-8100020260601104139.37ed7c03"
      },
      {
        "product_name": "Red Hat Directory Server 12.2 E4S for RHEL 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26639",
        "cpe": "cpe:/a:redhat:directory_server_e4s:12.2::el9",
        "package": "redhat-ds:12-9020020260615123354.1674d574"
      },
      {
        "product_name": "Red Hat Directory Server 12.4 E4S for RHEL 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26599",
        "cpe": "cpe:/a:redhat:directory_server_e4s:12.4::el9",
        "package": "redhat-ds:12-9040020260611130021.1674d574"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26456",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "389-ds-base-0:3.2.0-7.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26457",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "389-ds-base-0:3.0.6-18.el10_0"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26453",
        "cpe": "cpe:/o:redhat:rhel_els:7",
        "package": "389-ds-base-0:1.3.11.1-12.el7_9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26459",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "389-ds:1.4-8100020260601102239.25e700aa"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26463",
        "cpe": "cpe:/a:redhat:rhel_aus:8.4",
        "package": "389-ds:1.4-8040020260609102422.96015a92"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26463",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.4",
        "package": "389-ds:1.4-8040020260609102422.96015a92"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26460",
        "cpe": "cpe:/a:redhat:rhel_aus:8.6",
        "package": "389-ds:1.4-8060020260609102416.824efc52"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26460",
        "cpe": "cpe:/a:redhat:rhel_eus_long_life:8.6",
        "package": "389-ds:1.4-8060020260609102416.824efc52"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26454",
        "cpe": "cpe:/a:redhat:rhel_tus:8.8",
        "package": "389-ds:1.4-8080020260610125847.6dbb3803"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26454",
        "cpe": "cpe:/a:redhat:rhel_e4s:8.8",
        "package": "389-ds:1.4-8080020260610125847.6dbb3803"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26455",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "389-ds-base-0:2.8.0-7.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26452",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.2",
        "package": "389-ds-base-0:2.2.4-18.el9_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26464",
        "cpe": "cpe:/a:redhat:rhel_e4s:9.4",
        "package": "389-ds-base-0:2.4.5-25.el9_4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-06-17T00:00:00Z",
        "advisory": "RHSA-2026:26465",
        "cpe": "cpe:/a:redhat:rhel_eus:9.6",
        "package": "389-ds-base-0:2.6.1-21.el9_6"
      },
      {
        "product_name": "Red Hat Directory Server 13.2",
        "release_date": "2026-06-18T00:00:00Z",
        "advisory": "RHSA-2026:27125",
        "cpe": "cpe:/a:redhat:directory_server:13.2::el10",
        "package": "dirsrv/dirsrv-container-rhel10:1781714123"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Directory Server 12",
        "fix_state": "Affected",
        "package_name": "redhat-ds:12/389-ds-base",
        "cpe": "cpe:/a:redhat:directory_server:12"
      },
      {
        "product_name": "Red Hat Directory Server 13",
        "fix_state": "Will not fix",
        "package_name": "389-ds-base",
        "cpe": "cpe:/a:redhat:directory_server:13"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "389-ds-base",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-9064\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-9064"
    ],
    "name": "CVE-2026-9064",
    "mitigation": {
      "value": "Restrict network access to the LDAP port (389/tcp, 636/tcp) to trusted networks only using firewall rules or network ACLs. This prevents untrusted remote attackers from reaching the vulnerable code path.\nOptionally, lower the nsslapd-maxbersize configuration parameter to reduce the maximum BER message size accepted by the server. Note that this caps bytes, not the number of controls, and does not fully eliminate the amplification. Setting it too low may impact legitimate LDAP operations with large payloads.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Low",
    "public_date": "2026-06-09T00:00:00Z",
    "bugzilla": {
      "description": "openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption",
      "id": "2481880",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
    },
    "cvss3": {
      "cvss3_base_score": "5.9",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-131",
    "details": [
      "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\nThe FIPS modules are not affected by this issue.",
      "A flaw was found in OpenSSL. When processing attacker-supplied Cryptographic Message Syntax (CMS) data using password-based decryption, an attacker can choose a stream-mode Key Encryption Key (KEK) cipher. This can trigger a heap out-of-bounds read, potentially causing an application crash and leading to a Denial of Service (DoS). This vulnerability does not require password knowledge and can be exploited before authentication."
    ],
    "statement": "This is a Low impact denial of service due to a heap out-of-bounds read in `kek_unwrap_key()` when processing attacker-supplied CMS data with an attacker-chosen stream-mode KEK cipher. This flaw requires specific memory conditions (input buffer ending at a page boundary with an unmapped following page) to trigger a crash, which is uncommon in typical Red Hat environments. No information disclosure is possible, and FIPS modules are not affected.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25237",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "openssl-1:3.5.5-4.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25239",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-4.el9_8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-11T00:00:00Z",
        "advisory": "RHSA-2026:25239",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "openssl-1:3.5.5-4.el9_8"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-server-rhel9:1782159791"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29197",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782166952"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-07-01T00:00:00Z",
        "advisory": "RHSA-2026:34102",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1782890503"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1781525684"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/haproxy-rhel9:1781525671"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-rhel9:1781525693"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-06-16T00:00:00Z",
        "advisory": "RHSA-2026:26319",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1781525739"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "ovmf",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl10",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "mingw-openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "openssl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "compat-openssl11",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "edk2",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Out of support scope",
        "package_name": "shim-unsigned-aarch64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "shim-unsigned-x64",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Under investigation",
        "package_name": "jbcs-httpd24-openssl",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Core Services",
        "fix_state": "Under investigation",
        "package_name": "jbcs-openssl-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_core_services:1"
      },
      {
        "product_name": "Red Hat JBoss Web Server 6",
        "fix_state": "Under investigation",
        "package_name": "jws-optional-native-components-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
      },
      {
        "product_name": "Red Hat JBoss Web Server 7",
        "fix_state": "Under investigation",
        "package_name": "jws-optional-native-components-win6-x86_64.zip",
        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:7"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-9076\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-9076"
    ],
    "name": "CVE-2026-9076",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-20T22:19:32Z",
    "bugzilla": {
      "description": "libsolv: Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file",
      "id": "2460380",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460380"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-122",
    "details": [
      "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).",
      "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS)."
    ],
    "statement": "This Moderate impact heap buffer overflow in libsolv occurs when processing specially crafted `.solv` files with negative size values. Exploitation requires a victim to process attacker-controlled input, such as an untrusted `.solv` file, which can lead to a denial of service. The vulnerability is not easily exploitable without user interaction or specific application workflows that handle untrusted solvdb inputs.",
    "acknowledgement": "This issue was discovered by AISLE in partnership with Red Hat.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28236",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libsolv-0:0.7.33-5.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48818",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libsolv-0:0.7.29-8.el10_0.1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21333",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libsolv-main-0.7.38-2.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libsolv",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Fix deferred",
        "package_name": "libsolv",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libsolv",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite-capsule:el8/libsolv",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Update Infrastructure 4 for Cloud Providers",
        "fix_state": "Fix deferred",
        "package_name": "libsolv",
        "cpe": "cpe:/a:redhat:rhui:4::el8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-9149\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-9149\nhttps://github.com/openSUSE/libsolv/pull/617"
    ],
    "name": "CVE-2026-9149",
    "mitigation": {
      "value": "To mitigate this issue, avoid processing untrusted `.solv` files with libsolv or any applications that consume `.solv` input. Ensure that all `.solv` data processed by the system originates from trusted sources only.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-20T22:59:46Z",
    "bugzilla": {
      "description": "libsolv: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums",
      "id": "2460379",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460379"
    },
    "cvss3": {
      "cvss3_base_score": "6.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "verified"
    },
    "cwe": "CWE-121",
    "details": [
      "A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.",
      "A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system."
    ],
    "statement": "This Moderate impact flaw in libsolv's Debian metadata parser can lead to a denial of service due to a stack-based buffer overflow. Exploitation requires a victim to process specially crafted, untrusted Debian repository metadata containing malicious SHA384 or SHA512 checksums. While memory corruption occurs, reliable system compromise has not been demonstrated, and the vulnerability is not typically exposed in default Red Hat product configurations.",
    "acknowledgement": "This issue was discovered by Found by AISLE in partnership with Red Hat.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28236",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "libsolv-0:0.7.33-5.el10_2"
      },
      {
        "product_name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "release_date": "2026-07-31T00:00:00Z",
        "advisory": "RHSA-2026:48818",
        "cpe": "cpe:/o:redhat:enterprise_linux_eus:10.0",
        "package": "libsolv-0:0.7.29-8.el10_0.1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-27T00:00:00Z",
        "advisory": "RHSA-2026:21333",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libsolv-main-0.7.38-2.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-28T00:00:00Z",
        "advisory": "RHSA-2026:30649",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "libsolv-main-0.7.39-3.hum1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Fix deferred",
        "package_name": "libsolv",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "libsolv",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Fix deferred",
        "package_name": "libsolv",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Fix deferred",
        "package_name": "rhcos",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat Satellite 6",
        "fix_state": "Fix deferred",
        "package_name": "satellite-capsule:el8/libsolv",
        "cpe": "cpe:/a:redhat:satellite:6"
      },
      {
        "product_name": "Red Hat Update Infrastructure 4 for Cloud Providers",
        "fix_state": "Fix deferred",
        "package_name": "libsolv",
        "cpe": "cpe:/a:redhat:rhui:4::el8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-9150\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-9150\nhttps://github.com/openSUSE/libsolv/pull/616"
    ],
    "name": "CVE-2026-9150",
    "mitigation": {
      "value": "To mitigate this issue, ensure that libsolv only processes trusted and cryptographically signed Debian repository metadata. Avoid ingesting or processing `Packages` files from untrusted or unverified sources.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-05-22T14:11:41Z",
    "bugzilla": {
      "description": "nginx: ngx_http_rewrite_module: code execution and denial of service",
      "id": "2480746",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480746"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-122",
    "details": [
      "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "A flaw was found in the ngx_http_rewrite_module module of NGINX. When a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures and a replacement string that references multiple such captures in a redirect or arguments context, an unauthenticated attacker can send crafted HTTP requests and cause a heap-based buffer overflow in the worker process, potentially allowing code execution or a denial of service by forcing the process to restart."
    ],
    "statement": "To exploit this vulnerability, a rewrite directive must be configured with a regex pattern that uses distinct, overlapping PCRE captures and a replacement string referencing multiple such captures, limiting its exposure as this is not the default configuration. This issue allows an attacker to potentially execute arbitrary code or cause a denial of service by forcing the worker process to restart.\nDefault Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability.\nDue to these reasons, this flaw has been rated with an important severity.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29874",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "nginx-2:1.26.3-6.el10_2.4"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:28921",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "nginx:1.24-8100020260611094050.489197e6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-23T00:00:00Z",
        "advisory": "RHSA-2026:28212",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.24-9080020260610161820.9"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:28973",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx-2:1.20.1-28.el9_8.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-06-25T00:00:00Z",
        "advisory": "RHSA-2026:29151",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "nginx:1.26-9080020260609152155.9"
      },
      {
        "product_name": "Red Hat Discovery 2",
        "release_date": "2026-06-29T00:00:00Z",
        "advisory": "RHSA-2026:33313",
        "cpe": "cpe:/a:redhat:discovery:2::el9",
        "package": "discovery/discovery-ui-rhel9:1782756541"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-05-23T00:00:00Z",
        "advisory": "RHSA-2026:20351",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "nginx-main-1.30.2-1.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-rhel9:1784794818"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-rhel9:1784794778"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-07-23T00:00:00Z",
        "advisory": "RHSA-2026:44481",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-rhel9:1784795076"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Lightspeed proxy 1",
        "fix_state": "Affected",
        "package_name": "insights-proxy/insights-proxy-container-rhel9",
        "cpe": "cpe:/a:redhat:insights_proxy:1"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-9256\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-9256\nhttps://my.f5.com/manage/s/article/K000161377"
    ],
    "name": "CVE-2026-9256",
    "mitigation": {
      "value": "To mitigate this vulnerability, use named captures instead of unnamed captures in rewrite definitions.\nFor example, the following rewrite directive uses unnamed PCRE capture groups, $1 and $2:\n~~~\nrewrite ^/users/([0-9]+)/profile/(.*)$ /profile.php?id=$1&tab=$2 last;\n~~~\nTo mitigate this vulnerability for this example, replace $1 and $2 with the appropriate named captures, $user_id and $section:\n~~~\nrewrite ^/users/(?<user_id>[0-9]+)/profile/(?<section>.*)$ /profile.php?id=$user_id&tab=$section last;\n~~~",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-18T13:51:06Z",
    "bugzilla": {
      "description": "urwid: Urwid: Predictable session IDs lead to remote code execution and information disclosure",
      "id": "2502072",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502072"
    },
    "cvss3": {
      "cvss3_base_score": "8.1",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "status": "verified"
    },
    "cwe": "CWE-1241",
    "details": [
      "The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Python's Mersenne Twister PRNG, which is not cryptographically secure. Each call consumes approximately 30 bits of PRNG state, and the Mersenne Twister internal state is approximately 19,937 bits, so an attacker who observes approximately 334 session IDs (for example via the X-Urwid-ID HTTP response header) can fully reconstruct the internal state and predict all past and future session IDs (Path B). The same identifier is also used as the filename of a FIFO created in the world-listable /tmp directory (for example /tmp/urwid375487765176907690.in), so any local user on the host can list /tmp to enumerate active session tokens directly (Path A). With a valid session ID, an attacker can read the victim's terminal screen via the polling endpoint, inject keystrokes into the victim's session (yielding OS-level code execution with the session owner's privileges if the session runs a shell), and inject exit sequences or flood the FIFO to terminate or crash the session. A prior Bandit S311 warning on this usage was suppressed with # noqa: S311 rather than fixed",
      "A flaw was found in the urwid web display backend. This vulnerability arises from the use of a cryptographically insecure pseudo-random number generator (PRNG) for web session identifiers, making them predictable. An attacker could either observe enough session IDs to reconstruct the PRNG state or, if local, enumerate active session tokens from temporary files. Successful exploitation allows an attacker to read a victim's terminal screen, inject keystrokes leading to operating system-level code execution, or cause a denial of service by terminating the session."
    ],
    "statement": "The flaw is Important because predictable session identifiers in the urwid web display backend allow for remote code execution and information disclosure. Attackers can reconstruct the PRNG state by observing session IDs or enumerate active tokens from temporary files, leading to OS-level code execution with victim privileges.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58561",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "python-urwid-0:2.5.3-4.el10_2.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58562",
        "cpe": "cpe:/o:redhat:enterprise_linux:8",
        "package": "python-urwid-0:1.3.1-5.el8_10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57638",
        "cpe": "cpe:/o:redhat:rhel_aus:8.4",
        "package": "python-urwid-0:1.3.1-4.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57638",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.4",
        "package": "python-urwid-0:1.3.1-4.el8_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59198",
        "cpe": "cpe:/o:redhat:rhel_aus:8.6",
        "package": "python-urwid-0:1.3.1-4.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:59198",
        "cpe": "cpe:/o:redhat:rhel_eus_long_life:8.6",
        "package": "python-urwid-0:1.3.1-4.el8_6.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57637",
        "cpe": "cpe:/o:redhat:rhel_tus:8.8",
        "package": "python-urwid-0:1.3.1-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "release_date": "2026-08-20T00:00:00Z",
        "advisory": "RHSA-2026:57637",
        "cpe": "cpe:/o:redhat:rhel_e4s:8.8",
        "package": "python-urwid-0:1.3.1-4.el8_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58952",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "python-urwid-0:2.1.2-4.el9_8.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58954",
        "cpe": "cpe:/o:redhat:rhel_e4s:9.2",
        "package": "python-urwid-0:2.1.2-4.el9_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58953",
        "cpe": "cpe:/o:redhat:rhel_e4s:9.4",
        "package": "python-urwid-0:2.1.2-4.el9_4.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58955",
        "cpe": "cpe:/o:redhat:rhel_eus:9.6",
        "package": "python-urwid-0:2.1.2-4.el9_6.1"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "python-urwid",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Out of support scope",
        "package_name": "python-urwid",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-9323\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-9323\nhttps://github.com/urwid/urwid\nhttps://github.com/urwid/urwid/commit/24acd12f0d0598036d0d577f2ee63e4a27b4a3d9\nhttps://github.com/urwid/urwid/issues/1127\nhttps://github.com/urwid/urwid/pull/1128\nhttps://github.com/urwid/urwid/security/advisories/GHSA-rjwp-g85x-gmjv\nhttps://www.vulncheck.com/advisories/insecure-prng-and-information-exposure-in-urwid-web-display-backend"
    ],
    "name": "CVE-2026-9323",
    "mitigation": {
      "value": "To mitigate this vulnerability, it is recommended to disable the urwid web display backend if its functionality is not essential for your environment. If the urwid web display backend must remain active, restrict network access to the service to trusted clients only by implementing appropriate firewall rules. This will limit the exposure to remote attackers attempting to reconstruct session IDs. Additionally, ensure that local system configurations prevent unauthorized access to temporary files, which could otherwise allow local users to enumerate active session tokens. Any changes to service configurations may require a service restart to take effect.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-06T00:00:00Z",
    "bugzilla": {
      "description": "",
      "id": "",
      "url": ""
    },
    "cvss3": {
      "cvss3_base_score": "7.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "status": ""
    },
    "cwe": "",
    "details": [
      "urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (`preload_content=False`) when using Brotli support. The issue arises due to three independent code paths in `response.py` that bypass the `max_length` protection introduced in version 2.6.0 to mitigate CVE-2025-66471. Specifically, negative `max_length` values can be produced due to buffer arithmetic in `read()`, `flush_decoder` unconditionally overrides `max_length` to `-1`, and `_flush_decoder()` passes no limit at all, defaulting to unlimited decompression. This allows a malicious HTTP server to trigger an out-of-memory (OOM) condition by decompressing large payloads into memory, leading to a denial of service (DoS). The vulnerability affects urllib3 2.6.3 and Brotli 1.2.0 and impacts applications and libraries using `requests` or `urllib3` to stream content from untrusted sources."
    ],
    "statement": "",
    "package_state": [],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-9375\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-9375"
    ],
    "name": "CVE-2026-9375",
    "mitigation": {
      "value": "",
      "lang": ""
    },
    "csaw": false,
    "affected_release": []
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-07-03T06:18:44Z",
    "bugzilla": {
      "description": "curl: curl: Man-in-the-middle attack via SSH host key bypass",
      "id": "2496758",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
    },
    "cvss3": {
      "cvss3_base_score": "7.4",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "status": "verified"
    },
    "cwe": "CWE-347",
    "details": [
      "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.",
      "A flaw was found in curl. When a libcurl-based application uses SCP:// or SFTP:// for transfers and employs the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an untrusted server. This occurs if the server's host key type differs from the one stored in the known_hosts file. The callback mechanism fails to enforce the host key restriction, enabling a connection to an untrusted server and risking a man-in-the-middle attack."
    ],
    "statement": "This is an Important flaw where libcurl-based applications performing SCP or SFTP transfers with the CURLOPT_SSH_KEYFUNCTION callback may silently accept an untrusted server. This occurs when a server presents a host key type that differs from the one recorded in the known_hosts file, bypassing a critical host key verification and enabling potential man-in-the-middle attacks. The vulnerability requires specific application callback usage, not a general curl client default.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55450",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "curl-0:8.12.1-4.el10_2.3"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55439",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "curl-0:7.76.1-40.el9_8.5"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-08-17T00:00:00Z",
        "advisory": "RHSA-2026:55439",
        "cpe": "cpe:/o:redhat:enterprise_linux:9",
        "package": "curl-0:7.76.1-40.el9_8.5"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-06-24T00:00:00Z",
        "advisory": "RHSA-2026:29017",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "curl-main-8.21.0-0.1.hum1"
      },
      {
        "product_name": "Red Hat Hardened Images",
        "release_date": "2026-07-02T00:00:00Z",
        "advisory": "RHSA-2026:34975",
        "cpe": "cpe:/a:redhat:hummingbird:1",
        "package": "rust-main-1.96.1-1.hum1"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/cds-kubernetes-tp-rhel9:1787241211"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/installer-tp-rhel9:1787135742"
      },
      {
        "product_name": "Red Hat Update Infrastructure 5",
        "release_date": "2026-08-24T00:00:00Z",
        "advisory": "RHSA-2026:58981",
        "cpe": "cpe:/a:redhat:rhui:5::el9",
        "package": "rhui5/rhua-tp-rhel9:1787241260"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "curl",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat OpenShift Container Platform 4",
        "fix_state": "Affected",
        "package_name": "openshift/ose-rhel-coreos-9",
        "cpe": "cpe:/a:redhat:openshift:4"
      },
      {
        "product_name": "Red Hat OpenShift Dev Spaces",
        "fix_state": "Affected",
        "package_name": "devspaces/code-rhel9",
        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
      },
      {
        "product_name": "Red Hat Trusted Profile Analyzer",
        "fix_state": "Not affected",
        "package_name": "rhtpa/rhtpa-trustification-service-rhel9",
        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-9547\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-9547\nhttps://curl.se/docs/CVE-2026-9547.html\nhttps://curl.se/docs/CVE-2026-9547.json\nhttps://hackerone.com/reports/3751712"
    ],
    "name": "CVE-2026-9547",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Important",
    "public_date": "2026-06-09T07:22:25Z",
    "bugzilla": {
      "description": "DBI: DBI: Buffer overflow in error handling can lead to arbitrary code execution",
      "id": "2486734",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486734"
    },
    "cvss3": {
      "cvss3_base_score": "8.2",
      "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "status": "verified"
    },
    "cwe": "CWE-120",
    "details": [
      "DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.\nError messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.\nAttackers that can influence the error text in an application can trigger a buffer overflow.",
      "A flaw was found in DBI, a Perl database interface. This vulnerability allows an attacker to trigger a buffer overflow by manipulating error messages within an application. When specific error handling options are active, an attacker can provide oversized error text, which may lead to arbitrary code execution or a denial of service (DoS)."
    ],
    "statement": "Exploitation of this vulnerability requires that an attacker can provide values to an endpoint using perl-DBI which trigger certain errors. The attacker has no means of directly controlling the location and thus consequences of the buffer overflow, making the most likely outcome a denial-of-service due to corruption of the application's memory.",
    "affected_release": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38513",
        "cpe": "cpe:/o:redhat:enterprise_linux:10.2",
        "package": "perl-DBI-0:1.643-26.el10_2.1"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38901",
        "cpe": "cpe:/a:redhat:enterprise_linux:8",
        "package": "perl-DBI:1.641-8100020260624081239.69ef70f8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "release_date": "2026-07-13T00:00:00Z",
        "advisory": "RHSA-2026:38512",
        "cpe": "cpe:/a:redhat:enterprise_linux:9",
        "package": "perl-DBI-0:1.643-9.el9_8.1"
      },
      {
        "product_name": "Red Hat Insights proxy 1.5",
        "release_date": "2026-08-11T00:00:00Z",
        "advisory": "RHSA-2026:53371",
        "cpe": "cpe:/a:redhat:insights_proxy:1.5::el9",
        "package": "insights-proxy/insights-proxy-container-rhel9:1786433656"
      }
    ],
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Out of support scope",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Affected",
        "package_name": "perl-DBI",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-9698\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-9698\nhttps://github.com/perl5-dbi/dbi/commit/bfe5d73c162d2d1f761a639a0aa33aad6a9eb54e.patch\nhttps://metacpan.org/release/HMBRAND/DBI-1.648/changes"
    ],
    "name": "CVE-2026-9698",
    "mitigation": {
      "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Users are advised to identify network-accessible applications which use perl-DBI and ensure that only trusted users have access to those applications.",
      "lang": "en:us"
    },
    "csaw": false
  },
  {
    "threat_severity": "Moderate",
    "public_date": "2026-05-27T18:33:18Z",
    "bugzilla": {
      "description": "wireshark: NULL Pointer Dereference in Wireshark",
      "id": "2482358",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482358"
    },
    "cvss3": {
      "cvss3_base_score": "5.5",
      "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "status": "draft"
    },
    "cwe": "CWE-476",
    "details": [
      "ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service",
      "A flaw was found in the ROHC dissector in Wireshark. This issue occurs when malformed packets are decoded from a pcap file or the network, causing a NULL pointer dereference, resulting in a denial of service."
    ],
    "statement": "This issue will cause a crash in Wireshark with no other security impact. Also, this flaw can only be exploited when a malformed pcap file is processed. Due to these reasons, this vulnerability has been rated with a moderate severity.",
    "package_state": [
      {
        "product_name": "Red Hat Enterprise Linux 10",
        "fix_state": "Fix deferred",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:10"
      },
      {
        "product_name": "Red Hat Enterprise Linux 6",
        "fix_state": "Not affected",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:6"
      },
      {
        "product_name": "Red Hat Enterprise Linux 7",
        "fix_state": "Not affected",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:7"
      },
      {
        "product_name": "Red Hat Enterprise Linux 8",
        "fix_state": "Not affected",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:8"
      },
      {
        "product_name": "Red Hat Enterprise Linux 9",
        "fix_state": "Not affected",
        "package_name": "wireshark",
        "cpe": "cpe:/o:redhat:enterprise_linux:9"
      }
    ],
    "references": [
      "https://www.cve.org/CVERecord?id=CVE-2026-9759\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-9759\nhttps://gitlab.com/wireshark/wireshark/-/work_items/21243\nhttps://www.wireshark.org/security/wnpa-sec-2026-51.html"
    ],
    "name": "CVE-2026-9759",
    "mitigation": {
      "value": "If the ROHC protocol dissector is not being used, it can be disabled via the \"Enabled Protocols\" dialog box in the Wireshark GUI application. This will also disable the protocol dissector when using \"tshark\", the command line tool.\nSee the links below for instructions to disable a protocol in Wireshark, specifically the \"Control Protocol Dissection\" section and the \"disabled_protos\" configuration file option.\nhttps://www.wireshark.org/docs/wsug_html_chunked/ChCustProtocolDissectionSection.html\nhttps://www.wireshark.org/docs/wsug_html_chunked/ChAppFilesConfigurationSection.html",
      "lang": "en:us"
    },
    "csaw": false
  }
]